PT-2026-69068 · WordPress · Code Embed

CVE-2026-48093

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Code Embed WordPress plugin versions prior to 2.6.1
Description Stored Cross-Site Scripting (XSS) occurs through the external URL embed feature in post content. The software scans rendered content for URL embed tokens, fetches the remote URL, and inserts the response body into the page without output sanitization or an unfiltered html capability check. This allows a user with Contributor privileges to submit a pending post containing a URL token that executes arbitrary JavaScript when an Administrator or Editor previews or reviews the post.
Recommendations Update Code Embed WordPress plugin to version 2.6.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48093
GHSA-7C9X-PX5V-5HCP

Affected Products

Code Embed