Medium 6.4
2025-12-18< 2.7.11
CVE-2025-12885
Minimum safe version
2.7.11
Update to 2.7.11 or later to address 4 fixable vulnerabilities
CVE-2025-12885
Embed Any Document <= 2.7.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files Plugin <= 2.7.5 is vulnerable to Server Side Request Forgery (SSRF)
CVE-2023-23707