Impact
The PDF Embedder plugin for WordPress contains a vulnerability that permits authenticated users possessing contributor-level access or higher to retrieve configuration data through the enqueue_block_assets hook. The flaw enables extraction of license keys when the premium add-on is installed, while on Lite-only installs only non‑sensitive viewer configuration parameters are exposed. This constitutes a Sensitive Information Exposure (CWE‑200) with a CVSS score of 4.3, indicating a moderate risk to confidentiality.
Affected Systems
The affected product is the PDF Embedder WordPress plugin from smub, versions up to and including 4.9.3. No other version or vendor information is provided.
Risk and Exploitability
Exploitation requires an authenticated WordPress account with contributor permissions or higher and relies on the block editor triggering the enqueue_block_assets routine. The EPSS score is not available and the vulnerability is not listed in the K‑CAL KEV catalog. Therefore, while the likelihood of exploitation may be modest, the impact remains that an attacker could obtain configuration data or premium license keys, potentially aiding further attacks on the site.
OpenCVE Enrichment