Impact
The EmbedPress plugin contains a stored cross‑site scripting flaw that originates from the slidesShow block attribute being placed inside an unquoted data‑carousel‑options HTML attribute without proper input sanitization or output escaping. This allows an attacker who has at least contributor‑level access to embed arbitrary JavaScript into a page, which will execute in the browsers of any visitor that views the affected page.
Affected Systems
WordPress sites that install the EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, or Upload & Embed PDF documents plugin, for any version up to and including 4.6.6.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires an authenticated user with contributor or higher privileges to insert or edit content; once stored, the payload is served to all visitors, potentially allowing malicious scripts to run in their browsers.
OpenCVE Enrichment