Ajar in5 Embed

Ajar in5 Embed has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 9.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 0 high.

The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 2 of the records (100%).

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.

2 independent researchers contributed these findings, one record each. Ajar in5 Embed is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.

Strategic Overview

Avg CVSSCritical
9.8/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all Ajar in5 Embed vulnerabilities before they are exploited.

Most severe open issueCVSS 9.8CVE-2025-47642

Ajar in5 Embed <= 3.1.5 - Unauthenticated Arbitrary File Upload

Read the full analysis

Vulnerability Records

2 records
Ajar in5 Embed banner
Latestv3.1.5
4.2(5)
84/100
Last Updated
2024-12-12 (2y ago)
Active Installs
200+
Downloads
11,724
Requires WP
3.0.1+
Requires PHP
0+
Tested up to
WP 6.7.7
Created
2017-04-06 (10y ago)

in5 lets you export interactive HTML from Adobe InDesign. The Ajar in5 Embed plugin lets you insert your in5 HTML right inside a post with no coding.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C