Impact
The vulnerability is caused by insufficient sanitization of the 'unique' URL parameter in the EmbedPress plugin. An unauthenticated attacker can craft a URL containing malicious payloads that are reflected back into the page without proper escaping. If a victim follows the link, the browser will execute the injected script in the context of the WordPress site, enabling cookie theft, session hijacking, defacement, or other malicious actions. The weakness is a classic Reflected XSS, classified as CWE‑79.
Affected Systems
The flaw affects the wpdevteam EmbedPress suite, which includes PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, and Upload & Embed PDF documents. All releases up to and including version 4.6.5 are impacted; later, unspecified versions may have been patched.
Risk and Exploitability
The CVSS base score of 6.1 reflects a medium severity vulnerability that requires no authentication and depends on user interaction. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. Based on the plugin’s widespread use among WordPress sites, it is inferred that the potential business impact could be significant. The vulnerability is not currently listed in the CISA KEV catalog, indicating that no large‑scale active exploitation has been reported. Attackers would typically launch the exploit through phishing or social engineering links that embed the malicious 'unique' parameter, and success hinges on a victim clicking the link.
OpenCVE Enrichment