Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bplugins
Bplugins document Embedder Wordpress Wordpress wordpress |
|
| Vendors & Products |
Bplugins
Bplugins document Embedder Wordpress Wordpress wordpress |
Wed, 05 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 05 Nov 2025 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized access/modification/loss of data in all versions up to, and including, 2.0.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the "bplde_save_document_library", "bplde_get_all", "bplde_get_single", and "bplde_delete_document_library" functions. This makes it possible for unauthenticated attackers to create, read, update, and delete arbitrary document_library posts. | |
| Title | Document Embedder – Embed PDFs, Word, Excel, and Other Files <= 2.0.0 - Missing Authorization to Unauthenticated Document Manipulation | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:31:13.437Z
Reserved: 2025-10-28T11:35:02.879Z
Link: CVE-2025-12384
Updated: 2025-11-05T14:22:28.695Z
Status : Deferred
Published: 2025-11-05T07:15:32.570
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-12384
No data.
OpenCVE Enrichment
Updated: 2026-04-21T18:45:06Z