PDF Poster – let visitors read PDFs without leaving the page

PDF Poster – let visitors read PDFs without leaving the page has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 5 are fixed as of September 2026. Their average CVSS score is 5.6, and the most serious one scores 6.4 out of 10. 2026 was the busiest year with 3 disclosures.

The most common weakness is Cross-Site Scripting, behind 3 of the records (60%). Other recurring categories include Missing Authorization.

Every one of the 5 issues recorded for PDF Poster – let visitors read PDFs without leaving the page has a vendor fix available, so running the current release closes all known holes.

5 independent researchers contributed these findings, one record each. PDF Poster – let visitors read PDFs without leaving the page is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.6/ 10
Patch Coverage100%
Open

0

Fixed

5

Get automatic notifications for all PDF Poster – let visitors read PDFs without leaving the page vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2024-4367

PDF.js < 4.2.67 - Arbitrary JavaScript Execution

Read the full analysis

Vulnerability Records

5 records
PDF Poster – let visitors read PDFs without leaving the page banner
Latestv2.5.6

PDF Poster – let visitors read PDFs without leaving the page

bPlugins

Author

bPlugins

4.5(146)
90/100
Last Updated
2026-08-31 (13d ago)
Active Installs
20,000+
Downloads
762,378
Requires WP
5.0.3+
Requires PHP
7.1+
Tested up to
WP 7.1
Created
2016-11-30 (10y ago)

The Ultimate PDF Embedder Plugin for WordPress, Loved by Over 20,000+ Users PDF Poster | Documentation | Pricing | Support | Demo PDF Poster is a flexible plugin that allows you to embed PDF documents directly into WordPress posts, pages, widgets, or templates. Whether you’re sharing brochures, eBooks, business files, or portfolios, the plugin provides a responsive and accessible layout that works across all devices. Embed with the Gutenberg block, the [pdf_embed] shortcode, or the classic editor — whichever fits how you already work. The free version ships three viewers (the bundled PDF.js viewer, an interactive FlipBook and a Slider), independent height and width for desktop, tablet and mobile, print, download and full-screen buttons, social sharing, light/dark theming, RTL support and progressive loading for large files. Content protection, watermarking, the Adobe and Continuous Scroll viewers, popups and cloud imports are Pro. Key Features – Free Version Everything below is in the free plugin. No trial, no locked toggles. Three viewers, no configuration Default Viewer: The bundled Mozilla PDF.js engine — page navigation, zoom, text search and text selection, on desktop and mobile. FlipBook Viewer: A realistic page-turn book with a page-flip sound you can switch off. Slider Viewer: One page at a time, swipe or click through — ideal for brochures and menus. FlipBook from Images: Build a page-flip book from an ordered set of images instead of a PDF, for scanned or design-tool output. Embed it anywhere Two Gutenberg Blocks: The PDF Poster block to embed a file directly, and the PDF Poster Selector block to drop in a document you already saved. Shortcode: Use [pdf_embed] in any post, page, widget or template — every viewer option is available as an attribute. Classic Editor Metabox: A full settings panel on every PDF Poster document, so you never have to touch a block to configure a viewer. Responsive by device Separate Height & Width for Desktop, Tablet and Mobile: Set each breakpoint independently instead of forcing one size everywhere. Device Preview Switcher: Flip between desktop, tablet and mobile while you configure, in both the block and the metabox. Reading experience Viewer Theme (Light / Dark / Auto): Themes the viewer toolbar and background. The PDF page content is never altered. RTL Layout (Off / On / Auto): Flips the viewer and toolbar for Arabic, Hebrew and other right-to-left languages, across every viewer. Keyboard Navigation: Left and right arrow keys change pages in all viewers. Annotation Mode: Shows the notes, highlights, comments and clickable links already saved inside the PDF. Open PDF Links in a New Tab: Links clicked inside the document open in a new tab, keeping your page open. Filename Display: Show the document name above the viewer. Actions and sharing Print: Let visitors print straight from the viewer, or turn printing off. Download Button: One-click download above the viewer. Full-Screen Button with Your Own Label: Rename it for your language or your wording. Social Sharing: Facebook, X (Twitter), LinkedIn, Pinterest and email buttons, placed above or below the viewer, each one individually switchable. Styling Button and Title Styling: Background colour, text colour, font size and padding for the action buttons, plus the title font size — no CSS needed. Performance and reliability Fast Loading (Progressive Rendering): Streams large PDFs so the first page appears while the rest is still downloading. Google Doc Viewer Fallback: An optional second rendering path for browsers that mishandle inline PDFs (recommended for Edge). In the dashboard PDF Poster Dashboard: One place for your documents, demos, help and changelog. PDF Chatbot Assistant: Ask setup questions without leaving WordPress. Quick Embedder Defaults: Set the default height, width, filename display and download button once, and every new document starts there. Unlimited Documents: No cap on how many PDFs you embed. PDF Poster Pro – Unlock Advanced Features PDF Poster Pro adds the viewers, navigation, branding and document-protection controls that the free version deliberately leaves out. Watermark & Branding — new in Pro Text, Logo, or Both: Stamp your wording, your logo, or a logo with a caption over every page. Six Ready-Made Themes: Confidential, Draft Stamp, Sample Wash, Brand Corner, Logo Wash and Logo + Caption — each one carries its own angle, tiling and weight. A Custom theme is there when you want to set the angle yourself. Coverage, Strength, Size and Angle: From a single corner mark to a dense tile that cannot be cropped out, at five opacity steps and four sizes including fit-to-page. Dynamic Placeholders: Drop {site_name}, {post_title}, {file_name}, {page}, {pages}, {date}, {year}, {user_name}, {user_email} or {user_ip} into the text and it resolves per page and per visitor. Choose Who Sees It: Everyone, everyone except administrators (so you can proof the clean original), or logged-out visitors only. Choose Which Pages: All pages, the first page only, or everything except the cover. Anti-Leak Options: A per-visitor stamp that identifies whoever opened a leaked screenshot, plus tamper restore that puts the mark back if a visitor deletes it with browser dev tools. Live Preview: The block sidebar draws the mark with the same builder the front end uses, so what you see is what publishes. More viewers Adobe PDF Viewer: Rendering by the Adobe PDF Embed API, with Adobe’s own embed and view modes. Continuous Scroll Viewer: Built for long reports — every page in one uninterrupted scroll. Reader Mode: The document and nothing else. No toolbar, no frame, no distractions. Navigation controls Thumbnail Sidebar: Show the page thumbnails panel, and choose whether it opens by default. Initial Page and Default Zoom: Open on page 12 at 125% if that is where the reader should start. Horizontal Scrollbar: Make horizontal scrolling the default for wide documents. Document protection Disable Right-Click and Copying: Block the context menu and copy shortcuts on your documents. Disable Text Selection: Stop text being dragged out of the viewer. Suppress Blocked-Action Alerts: Enforce protection quietly, without warning pop-ups. Popup viewer Open PDFs in a Modal: Keep the page clean and load the document on click. Button or Image Trigger: Trigger from a styled button or from any image, with your own alignment, image dimensions and an optional PDF icon overlay. Full button control Rename the Download Button: Your label, your language. Show or Hide the Full-Screen Button, and optionally open full-screen in a new tab. Move the Action Bar: Put Print, Download and Full-Screen above or below the viewer. Cloud and workflow Google Drive Picker and Dropbox Import: Pull a PDF straight from cloud storage instead of uploading it twice. Presets: Save a viewer configuration once and apply it site-wide, including to classic shortcodes. Custom CSS and Custom Classes: Global CSS plus a per-embed class, for full design control. Always Load the Latest Version: Replace the file and every embed updates — no re-linking. Quick Embedder for the Classic Editor: An embed tool and shortcode generator built into the classic editor. Priority One-on-One Support: Straight to the developers. Coming soon in Pro: in-viewer Ads and per-document Analytics — both already sketched in the interface, shipping in a later release. Try the PDF Poster PRO – Unlock all premium features now! How to Use PDF Poster – Step-by-Step Guide Getting started with PDF Poster is quick and easy! Step-by-Step Instructions After installing, go to the “PDF Poster” menu in your WordPress dashboard Upload one or more PDF documents Copy the Shortcode shown in the editor or PDF list Paste the shortcode into any post, page, or widget area Hit the Publish button. Enjoy your beautifully embedded PDF! Gutenberg Block Integration Using the block editor? Here’s how to embed PDFs in just a few clicks: Open a post or page in the WordPress editor Click the + icon or use the slash command (/pdf) Find PDF Poster under the Layout Elements category Click the icon to insert the block Choose your PDF from the media library Hit Publish and enjoy! Live Demo | Get PDF Poster PRO Shortcode Usage Shortcode [pdf_embed url=”https://example.com/document.pdf” width=”100%” height=”842px” print=”true” title=”My PDF Document” download_btn=”true” fullscreen_btn_text=”View in Fullscreen”] Attributes url (required): The URL of the PDF file. Default: null Example: url="https://example.com/document.pdf" width (optional): Width of the PDF viewer. Default: "100%" Example: width="80%" height (optional): Height of the PDF viewer. Default: "842px" Example: height="600px" print (optional): Display a print button. Accepted values: "true", "false" Default: "false" Example: print="true" title (optional): Title displayed above the PDF viewer. Default: null Example: title="Document Title" download_btn (optional): Display a download button. Accepted values: "true", "false" Default: "false" Example: download_btn="true" fullscreen_btn_text (optional): Text for the fullscreen button. Default: "View Fullscreen" Example: fullscreen_btn_text="Open Fullscreen" User Feedback ⭐⭐⭐⭐⭐ Weronika Zielinska – Empp ❛❛A great plugin that makes it easy to add the necessary posters and pdfs! It makes it very easy to quickly create a website. I definitely recommend it and we will definitely use it always.❜❜ –empp ⭐⭐⭐⭐⭐ good plugin ❛❛This pdf poster plugin does really solve my requirement.❜❜ –a2zdoctors – Did you like this plugin? Dislike it? Have a feature request? Please share your feedback with us Check out our other WordPress Plugins- Html5 Video Player – Display videos as single and playlist in multiple skins. Html5 Audio Player – Listen audios with awesome visuals. StreamCast – Customizable radio player with different skins. 3D Viewer – Embed 3D models and 3D products with interaction. Advanced Post Block – Show posts and custom posts in different layouts. Source Code You can find the source code, report bugs, and contribute to the development of this plugin on our GitHub repository: PDF Poster on GitHub This plugin bundles the following third-party JavaScript/PHP libraries. PDF.js v3.38.1 (Legacy build) File: assets/pdfjs-new/generic-legacy/pdf.js Source: https://mozilla.github.io/pdf.js/ GitHub: https://github.com/mozilla/pdf.js License: Apache-2.0 – https://github.com/mozilla/pdf.js/blob/master/LICENSE Purpose: High-performance, standard-compliant PDF rendering in the browser. Freemius SDK v2.13.1 Source: https://freemius.com/ GitHub: https://github.com/Freemius/wordpress-sdk License: GPLv3 – https://github.com/Freemius/wordpress-sdk/blob/master/LICENSE.txt Purpose: Provides licensing, updates, and opt-in usage tracking/analytics. Codestar Framework v2.3.0 File: vendor/codestar-framework/ Source: https://codestarframework.com/ GitHub: https://github.com/Codestar/codestar-framework License: GPLv2 – https://github.com/Codestar/codestar-framework/blob/master/LICENSE Purpose: Lightweight and modern options framework for settings and metaboxes. bpl-tools Source / GitHub: https://github.com/bPlugins/bpl-tools License: GPL-2.0-or-later – https://www.gnu.org/licenses/gpl-2.0.html Purpose: Shared utility library providing admin dashboard components and common Gutenberg editor controls. External Services: The library may connect to bPlugins, WordPress.org, and Freemius services for product data and checkout functionality. See full details: https://github.com/bPlugins/bpl-tools#external-requests–why-they-are-made Montserrat Font (Google Fonts) Source: https://fonts.google.com/specimen/Montserrat License: SIL Open Font License (OFL) – https://scripts.sil.org/OFL Purpose: Primary typeface for the plugin interface. This plugin optionally connects to the following external services for enhanced functionality. Google Docs Viewer Source: https://docs.google.com/gview Purpose: Used as a fallback rendering engine when native PDF.js fails or in specific viewer modes. Terms of Service: https://policies.google.com/terms Privacy Policy: https://policies.google.com/privacy Adobe PDF Embed API Source: https://documentservices.adobe.com/view-sdk/main.js Purpose: Provides an alternative high-quality viewing experience (requires user configuration). Terms of Use: https://www.adobe.com/legal/terms.html Privacy Policy: https://www.adobe.com/privacy/policy.html

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C