Description
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
Published: 2026-08-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated cross‑site scripting vulnerability exists in the EmbedPress plugin for WordPress versions 4.5.6 and earlier. An attacker can inject arbitrary client‑side script that will execute in the browsers of any user browsing content processed by the vulnerable plugin. This flaw falls under CWE‑79 and can lead to session hijacking, defacement, or the execution of malicious payloads in targeted users’ browsers. The impact is confined to the confidentiality and integrity of the web sessions of visitors to the affected site.

Affected Systems

The vulnerability affects the WPDeveloper EmbedPress plugin for WordPress, specifically all releases up to and including version 4.5.6. Sites that have not upgraded beyond 4.5.6 are exposed.

Risk and Exploitability

The CVSS score for this issue is 7.1, indicating a high severity. The EPSS score is currently unavailable, so the precise likelihood of exploitation cannot be quantified, but the presence of an unauthenticated XSS vector suggests that attackers could easily exploit the flaw by linking users to a crafted URL or embedding malicious content. The vulnerability is not listed in the CISA KEV catalog, indicating no known targeted exploits at the time of this analysis. The attack vector is primarily through honest user interaction with a compromised or maliciously crafted page, inferring that targeted phishing or social engineering could be employed to get users to load the XSS payload.

Generated by OpenCVE AI on August 6, 2026 at 15:23 UTC.

Remediation

Vendor Solution

Update the WordPress EmbedPress Plugin to the latest available version (at least 4.6.0).


OpenCVE Recommended Actions

  • Apply the latest WordPress EmbedPress Plugin update (4.6.0 or later).
  • Ensure that the plugin is removed or disabled on sites that cannot be upgraded immediately, to eliminate the attack surface.
  • After updating, verify that the plugin no longer renders any user‑supplied content without proper sanitization, and perform a quick script injection test against a non‑production copy of the site to confirm remediation has succeeded.

Generated by OpenCVE AI on August 6, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdeveloper
Wpdeveloper embedpress
Vendors & Products Wordpress
Wordpress wordpress
Wpdeveloper
Wpdeveloper embedpress

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
Title WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wpdeveloper Embedpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:48:10.314Z

Reserved: 2026-07-13T06:13:44.978Z

Link: CVE-2026-61961

cve-icon Vulnrichment

Updated: 2026-08-06T14:48:06.695Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:15:01Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')