Impact
An unauthenticated cross‑site scripting vulnerability exists in the EmbedPress plugin for WordPress versions 4.5.6 and earlier. An attacker can inject arbitrary client‑side script that will execute in the browsers of any user browsing content processed by the vulnerable plugin. This flaw falls under CWE‑79 and can lead to session hijacking, defacement, or the execution of malicious payloads in targeted users’ browsers. The impact is confined to the confidentiality and integrity of the web sessions of visitors to the affected site.
Affected Systems
The vulnerability affects the WPDeveloper EmbedPress plugin for WordPress, specifically all releases up to and including version 4.5.6. Sites that have not upgraded beyond 4.5.6 are exposed.
Risk and Exploitability
The CVSS score for this issue is 7.1, indicating a high severity. The EPSS score is currently unavailable, so the precise likelihood of exploitation cannot be quantified, but the presence of an unauthenticated XSS vector suggests that attackers could easily exploit the flaw by linking users to a crafted URL or embedding malicious content. The vulnerability is not listed in the CISA KEV catalog, indicating no known targeted exploits at the time of this analysis. The attack vector is primarily through honest user interaction with a compromised or maliciously crafted page, inferring that targeted phishing or social engineering could be employed to get users to load the XSS payload.
OpenCVE Enrichment