THREAT OPS › Threat News › [NVD] CVE-2026-7526 (MEDIUM 4.3) — The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration da
[NVD] CVE-2026-7526 (MEDIUM 4.3) — The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration da
CVE-2026-7526 CVSS: 4.3 MEDIUM Published: 2026-05-28T09:16:48.700
The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when the premium add-
Indicators of compromise
- CVE-2026-7526cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-7526