PT-2026-69068 · WordPress · Code Embed
CVE-2026-48093
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Code Embed WordPress plugin versions prior to 2.6.1
Description
Stored Cross-Site Scripting (XSS) occurs through the external URL embed feature in post content. The software scans rendered content for URL embed tokens, fetches the remote URL, and inserts the response body into the page without output sanitization or an
unfiltered html capability check. This allows a user with Contributor privileges to submit a pending post containing a URL token that executes arbitrary JavaScript when an Administrator or Editor previews or reviews the post.Recommendations
Update Code Embed WordPress plugin to version 2.6.1.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Code Embed