Description
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and including, 4.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is a regression: the esc_url() wrapper that remediated the equivalent CVE-2023-5749 in version 3.9.2 was removed in version 4.3.0 during a refactor that introduced the 'unique' parameter.
Published: 2026-09-18
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Reflected Cross‑Site Scripting that permits arbitrary script execution in a victim's browser
Action: Patch
AI Analysis

Impact

The vulnerability is caused by insufficient sanitization of the 'unique' URL parameter in the EmbedPress plugin. An unauthenticated attacker can craft a URL containing malicious payloads that are reflected back into the page without proper escaping. If a victim follows the link, the browser will execute the injected script in the context of the WordPress site, enabling cookie theft, session hijacking, defacement, or other malicious actions. The weakness is a classic Reflected XSS, classified as CWE‑79.

Affected Systems

The flaw affects the wpdevteam EmbedPress suite, which includes PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, and Upload & Embed PDF documents. All releases up to and including version 4.6.5 are impacted; later, unspecified versions may have been patched.

Risk and Exploitability

The CVSS base score of 6.1 reflects a medium severity vulnerability that requires no authentication and depends on user interaction. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. Based on the plugin’s widespread use among WordPress sites, it is inferred that the potential business impact could be significant. The vulnerability is not currently listed in the CISA KEV catalog, indicating that no large‑scale active exploitation has been reported. Attackers would typically launch the exploit through phishing or social engineering links that embed the malicious 'unique' parameter, and success hinges on a victim clicking the link.

Generated by OpenCVE AI on September 19, 2026 at 20:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest EmbedPress release that fixes the XSS flaw.
  • If an update cannot be performed immediately, uninstall or deactivate the plugin to eliminate the vulnerable endpoint.
  • Configure a web application firewall to block or sanitize requests containing the 'unique' query parameter.

Generated by OpenCVE AI on September 19, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam embedpress – Pdf Embedder, 3d Pdf Flipbook, Google Reviews, Youtube Videos, Upload & Embed Pdf Documents
Vendors & Products Wordpress
Wordpress wordpress
Wpdevteam
Wpdevteam embedpress – Pdf Embedder, 3d Pdf Flipbook, Google Reviews, Youtube Videos, Upload & Embed Pdf Documents

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all versions up to, and including, 4.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is a regression: the esc_url() wrapper that remediated the equivalent CVE-2023-5749 in version 3.9.2 was removed in version 4.3.0 during a refactor that introduced the 'unique' parameter.
Title EmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' Parameters
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpdevteam Embedpress – Pdf Embedder, 3d Pdf Flipbook, Google Reviews, Youtube Videos, Upload & Embed Pdf Documents
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-18T11:35:19.335Z

Reserved: 2026-09-11T15:13:46.881Z

Link: CVE-2026-89330

cve-icon Vulnrichment

Updated: 2026-09-18T11:35:15.278Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:51.193

Modified: 2026-09-18T13:23:37.403

Link: CVE-2026-89330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:32Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')