Description
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
Published: 2026-08-20
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an unauthenticated Cross‑Site Scripting flaw present in all Tagembed plugin installations version 7.4 and earlier. The flaw allows an attacker to inject malicious scripts that are executed in the browsers of any user visiting a page that displays a Tagembed widget. Because the attack does not require authentication, any visitor can be targeted, leading to data theft, credential compromise, or defacement. The weakness is identified as CWE‑79.

Affected Systems

The affected product is the WordPress Tagembed plugin, all releases up to and including 7.4. Those running an earlier, unpatched version are vulnerable. WordPress sites that have the Tagembed widget active are at risk.

Risk and Exploitability

The vulnerability carries a CVSS base score of 7.1, indicating high severity. No EPSS value is available, and the vulnerability is not listed in CISA's KEV catalog, so no confirmed exploitation reports are known. Because the flaw can be triggered by unauthenticated visitors using a specially crafted Tagembed entry, the attack surface is broad, but no privileges or network access are required beyond normal web traffic. The lack of known exploits reduces immediate risk, yet the high severity and wide attack surface warrant timely remediation.

Generated by OpenCVE AI on August 20, 2026 at 21:07 UTC.

Remediation

Vendor Solution

Update the WordPress Tagembed Plugin to the latest available version (at least 7.5).


OpenCVE Recommended Actions

  • Upgrade the Tagembed plugin to version 7.5 or later, which removes the XSS vulnerability.
  • If an upgrade is not yet possible, disable or remove the Tagembed widget until a patch is applied.
  • Apply a site‑wide Content Security Policy that restricts inline scripts and disallows unsafe-eval to mitigate potential XSS impact.
  • Ensure WordPress core and other plugins are up to date, and regularly scan the site for injected scripts.

Generated by OpenCVE AI on August 20, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
Title WordPress Tagembed plugin <= 7.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T16:27:29.351Z

Reserved: 2026-07-27T14:00:04.572Z

Link: CVE-2026-66590

cve-icon Vulnrichment

Updated: 2026-08-20T16:20:15.346Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:32.930

Modified: 2026-08-20T17:19:24.977

Link: CVE-2026-66590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T21:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')