PT-2026-103028 · WordPress · Embedpress
CVE-2026-85001
·
Published
2026-09-30
·
Updated
2026-09-30
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EmbedPress versions prior to 4.6.7
Description
Insufficient sanitization and escaping of an Elementor widget setting before it is output into an HTML attribute allows users with the Contributor role or higher to perform a Cross-Site Scripting (XSS) attack. This occurs when arbitrary web scripts are injected and subsequently executed in the browser of a user viewing the affected content.
Recommendations
Update EmbedPress to version 4.6.7 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Embedpress