All 3 CVE vulnerabilities found in Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files, with AI-generated Chinese analysis, references, and POCs.
Vendor: Awsm Innovations
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-12885 | Embed Any Document <= 2.7.10 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 | 6.4 | Medium | 2025-12-18 |
| CVE-2025-1043 | Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files <= 2.7.5 - Authenticated (Contributor+) Blind Server-Side Request Forgery via embeddoc Shortcode CWE-918 | 6.4 | Medium | 2025-02-20 |
| CVE-2023-23707 | WordPress Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files Plugin <= 2.7.1 is vulnerable to Cross Site Scripting (XSS) CWE-79 | 5.9 | Medium | 2023-03-23 |
All 3 known CVE vulnerabilities affecting Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files with full Chinese analysis, references, and POCs where available.