EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents <= 4.5.6 - Unauthenticated Stored Cross-Site Scripting
high
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated at...
- CVSS:
- 7.2
- Affected:
- up to 4.5.6
- Fixed in:
- 4.6.0
- Disclosed:
- Aug 3, 2026
CVE-2026-61961 on NVD →
EmbedPress <= 4.6.0 - Unauthenticated Blind Server-Side Request Forgery
high
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations ori...
- CVSS:
- 7.2
- Affected:
- up to 4.6.0
- Fixed in:
- 4.6.1
- Disclosed:
- Jul 27, 2026
CVE-2026-10526 on NVD →
EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute
medium
The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 6.4
- Affected:
- up to 4.5.3
- Fixed in:
- 4.5.4
- Disclosed:
- Jun 5, 2026
CVE-2026-7796 on NVD →
EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more <= 4.5.2 - Unauthenticated Information Exposure
medium
The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.2. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 4.5.2
- Fixed in:
- 4.5.3
- Disclosed:
- Jun 1, 2026
CVE-2026-48872 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 4.1.4
unknown
[en] The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘provider_name parameter in all versions up to, and including, 4.1.3 due to insufficient in...
- Affected:
- up to 4.1.4
- Fixed in:
- 4.1.4
- Disclosed:
- Nov 28, 2024
CVE-2024-11203 on NVD →
EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name'
medium
The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘provider_name parameter in all versions up to, and including, 4.1.3 due to insufficient input s...
- CVSS:
- 6.4
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Nov 27, 2024
CVE-2024-11203 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 4.0.5
unknown
[en] Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a through 4.0.4.
- Affected:
- up to 4.0.5
- Fixed in:
- 4.0.5
- Disclosed:
- Nov 1, 2024
CVE-2024-38707 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 4.1.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.14.
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Oct 28, 2024
CVE-2024-50461 on NVD →
EmbedPress <= 4.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 4.0.14
- Fixed in:
- 4.1.0
- Disclosed:
- Oct 24, 2024
CVE-2024-50461 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 4.0.9
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.8.
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.9
- Disclosed:
- Aug 29, 2024
CVE-2024-43936 on NVD →
EmbedPress <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 4.0.8
- Fixed in:
- 4.0.9
- Disclosed:
- Aug 26, 2024
CVE-2024-43936 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 4.0.10
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9.
- Affected:
- up to 4.0.10
- Fixed in:
- 4.0.10
- Disclosed:
- Aug 19, 2024
CVE-2024-43328 on NVD →
EmbedPress <= 4.0.9 - Unauthenticated Local File Inclusion
critical
The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.0.9 via the 'page_type' parameter. This makes it possible for unauthent...
- CVSS:
- 9.8
- Affected:
- up to 4.0.9
- Fixed in:
- 4.0.10
- Disclosed:
- Aug 16, 2024
CVE-2024-43328 on NVD →
EmbedPress <= 4.0.4 - Missing Authorization
medium
The EmbedPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions like get_instagram_userdata_ajax, sync_instagram_data_ajax, and delete_instagram_account in versions up to, and including, 4.0.4. This makes it possible for authenticated attack...
- CVSS:
- 5.3
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.5
- Disclosed:
- Jul 11, 2024
CVE-2024-38707 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.8.4
unknown
[en] Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- Jun 21, 2024
CVE-2023-51375 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.11
unknown
[en] The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the PDF Widget URL in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escap...
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.11
- Disclosed:
- Jun 13, 2024
CVE-2024-1565 on NVD →
EmbedPress <= 3.9.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via PDF Widget URL
medium
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the PDF Widget URL in all versions up to, and including, 3.9.10 due to insufficient input sanitization and output escaping o...
- CVSS:
- 6.4
- Affected:
- up to 3.9.10
- Fixed in:
- 3.9.11
- Disclosed:
- Jun 12, 2024
CVE-2024-1565 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.9
unknown
[en] Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8.
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.9
- Disclosed:
- Jun 9, 2024
CVE-2024-31284 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.12
unknown
[en] Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.11.
- Affected:
- up to 3.9.12
- Fixed in:
- 3.9.12
- Disclosed:
- Jun 9, 2024
CVE-2024-31274 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 4.0.2
unknown
[en] The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's EmbedPress PDF widget in all versions up to, and including, 4.0.1 d...
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Jun 5, 2024
CVE-2024-5571 on NVD →
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget
medium
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's EmbedPress PDF widget in all versions up to, and including, 4.0.1 due to...
- CVSS:
- 6.4
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.2
- Disclosed:
- Jun 4, 2024
CVE-2024-5571 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.13
unknown
[en] The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validation on the PDF embed block in all versions up to, and includi...
- Affected:
- up to 3.9.13
- Fixed in:
- 3.9.13
- Disclosed:
- May 23, 2024
CVE-2024-1803 on NVD →
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Insufficient Authorization Checks to Block Usual
medium
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validation on the PDF embed block in all versions up to, and including, 3...
- CVSS:
- 4.3
- Affected:
- up to 3.9.12
- Fixed in:
- 3.9.13
- Disclosed:
- May 22, 2024
CVE-2024-1803 on NVD →
PDF.js < 4.2.67 - Arbitrary JavaScript Execution
medium
PDF.js is vulnerable to Arbitrary JavaScript Execution in versions prior to 4.2.67. This is due to a missing type check when handling fonts. This makes it possible for authenticated attackers, with contributor-level or above permissions, to execute arbitrary JavaScript if they can successfully trick a user into opening...
- CVSS:
- 6.4
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.3
- Disclosed:
- May 20, 2024
CVE-2024-4367 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 4.0.3
unknown
[en] A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- May 14, 2024
CVE-2024-4367 on NVD →
EmbedPress Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
medium
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.9.16 due to insufficient input sanitization and outpu...
- CVSS:
- 6.4
- Affected:
- up to 3.9.16
- Fixed in:
- 3.9.17
- Disclosed:
- May 9, 2024
CVE-2024-4316 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.17
unknown
[en] The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.9.16 due to insufficient input sanitization and...
- Affected:
- up to 3.9.17
- Fixed in:
- 3.9.17
- Disclosed:
- May 9, 2024
CVE-2024-4316 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.15
unknown
[en] The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
'embedpress_calendar' shortcode in all versions up to, and including, 3.9.14 due to insuffic...
- Affected:
- up to 3.9.15
- Fixed in:
- 3.9.15
- Disclosed:
- Apr 9, 2024
CVE-2024-3244 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.15
unknown
[en] The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Youtube block in all versions up to, and including, 3.9.14 due to insufficient input sanitizat...
- Affected:
- up to 3.9.15
- Fixed in:
- 3.9.15
- Disclosed:
- Apr 6, 2024
CVE-2024-3245 on NVD →
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block
medium
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Youtube block in all versions up to, and including, 3.9.14 due to insufficient input sanitization a...
- CVSS:
- 6.4
- Affected:
- up to 3.9.14
- Fixed in:
- 3.9.15
- Disclosed:
- Apr 5, 2024
CVE-2024-3245 on NVD →
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's
'embedpress_calendar' shortcode in all versions up to, and including, 3.9.14 due to insufficient...
- CVSS:
- 6.4
- Affected:
- up to 3.9.14
- Fixed in:
- 3.9.15
- Disclosed:
- Apr 5, 2024
CVE-2024-3244 on NVD →
EmbedPress <= 3.9.8 - Missing Authorization via handle_calendly_data
medium
The EmbedPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handle_calendly_data() function in versions up to, and including, 3.9.8. This makes it possible for unauthenticated attackers to update calendly settings.
- CVSS:
- 5.3
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.9
- Disclosed:
- Apr 5, 2024
CVE-2024-31284 on NVD →
EmbedPress <= 3.9.11 - Missing Authorization
medium
The EmbedPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_source_data and save_source_data functions in versions up to, and including, 3.9.11. This makes it possible for unauthenticated attackers to modify data sources.
- CVSS:
- 5.3
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.12
- Disclosed:
- Apr 5, 2024
CVE-2024-31274 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.13
unknown
[en] The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress document widget in all versions up to, and including, 3.9.12 due to insufficient input sanit...
- Affected:
- up to 3.9.13
- Fixed in:
- 3.9.13
- Disclosed:
- Mar 23, 2024
CVE-2024-2688 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.13
unknown
[en] The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress widget 'embedpress_pro_twitch_theme ' attribute in all versions up to, and including, 3.9.12...
- Affected:
- up to 3.9.13
- Fixed in:
- 3.9.13
- Disclosed:
- Mar 23, 2024
CVE-2024-2468 on NVD →
EmbedPress <= 3.9.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Attribute
medium
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress widget 'embedpress_pro_twitch_theme ' attribute in all versions up to, and including, 3.9.12 due...
- CVSS:
- 6.4
- Affected:
- up to 3.9.12
- Fixed in:
- 3.9.13
- Disclosed:
- Mar 22, 2024
CVE-2024-2468 on NVD →
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Authenticated (Contributor+) Stored Cross-site Scripting via 'embedpress_doc_custom_color'
medium
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the EmbedPress document widget in all versions up to, and including, 3.9.12 due to insufficient input sanitizati...
- CVSS:
- 5.4
- Affected:
- up to 3.9.12
- Fixed in:
- 3.9.13
- Disclosed:
- Mar 22, 2024
CVE-2024-2688 on NVD →
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block
medium
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wistia embed block in all versions up to, and including, 3.9.10 due to insufficient input sanitizat...
- CVSS:
- 6.4
- Affected:
- up to 3.9.10
- Fixed in:
- 3.9.11
- Disclosed:
- Mar 7, 2024
CVE-2024-1802 on NVD →
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget
medium
The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed widget in all versions up to, and including, 3.9.10 due to insufficient input sanitization an...
- CVSS:
- 6.4
- Affected:
- up to 3.9.10
- Fixed in:
- 3.9.11
- Disclosed:
- Mar 7, 2024
CVE-2024-2128 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.11
unknown
[en] The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wistia embed block in all versions up to, and including, 3.9.10 due to insufficient input sani...
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.11
- Disclosed:
- Mar 7, 2024
CVE-2024-1802 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.11
unknown
[en] The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed widget in all versions up to, and including, 3.9.10 due to insufficient input sanitizati...
- Affected:
- up to 3.9.11
- Fixed in:
- 3.9.11
- Disclosed:
- Mar 7, 2024
CVE-2024-2128 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.9
unknown
[en] The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.9.8 due to insufficient input sanitization and output...
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.9
- Disclosed:
- Feb 20, 2024
CVE-2024-1349 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.9
unknown
[en] The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Calendar Widget Link in all versions up to, and including, 3.9.8 due to insufficient input sanitization and...
- Affected:
- up to 3.9.9
- Fixed in:
- 3.9.9
- Disclosed:
- Feb 20, 2024
CVE-2024-1425 on NVD →
EmbedPress <= 3.9.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via Google Calendar Widget Link
medium
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Calendar Widget Link in all versions up to, and including, 3.9.8 due to insufficient input sanitization and outpu...
- CVSS:
- 6.4
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.9
- Disclosed:
- Feb 14, 2024
CVE-2024-1425 on NVD →
EmbedPress <= 3.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.9.8 due to insufficient input sanitization and output esca...
- CVSS:
- 6.4
- Affected:
- up to 3.9.8
- Fixed in:
- 3.9.9
- Disclosed:
- Feb 14, 2024
CVE-2024-1349 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.6
unknown
[en] The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed_oembed_html shortcode in all versions up to 3.9.5 (exclusive) due to insufficient input sanitization...
- Affected:
- up to 3.9.6
- Fixed in:
- 3.9.6
- Disclosed:
- Jan 3, 2024
CVE-2023-6986 on NVD →
EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's embed_oembed_html shortcode in all versions up to 3.9.5 (exclusive) due to insufficient input sanitization and...
- CVSS:
- 6.4
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.6
- Disclosed:
- Jan 2, 2024
CVE-2023-6986 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.2
unknown
[en] The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Dec 11, 2023
CVE-2023-5749 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.2
unknown
[en] The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Dec 11, 2023
CVE-2023-5750 on NVD →
EmbedPress <= 3.9.4 - Missing Authorization
medium
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_source_data() and delete_source_data() functions in all versions up to 3.9.5...
- CVSS:
- 5.3
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.5
- Disclosed:
- Dec 8, 2023
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.5
unknown
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_source_data() and delete_source_data() functions in all versions up to 3.9.5...
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.5
- Disclosed:
- Dec 8, 2023
EmbedPress <= 3.9.1 - Reflected Cross-Site Scripting
medium
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the hash parameter in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping...
- CVSS:
- 6.1
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.2
- Disclosed:
- Nov 17, 2023
CVE-2023-5750 on NVD →
EmbedPress <= 3.9.1 - Reflected Cross-Site Scripting
medium
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'password' parameter in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output es...
- CVSS:
- 6.1
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.2
- Disclosed:
- Nov 17, 2023
CVE-2023-5749 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.2
unknown
Update the WordPress EmbedPress plugin to the latest available version (at least 3.9.2).
WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress EmbedPress Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML paylo...
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Nov 17, 2023
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.2
unknown
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the hash parameter in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping...
- Affected:
- up to 3.9.2
- Fixed in:
- 3.9.2
- Disclosed:
- Nov 17, 2023
EmbedPress <= 3.8.3 - Cross-Site Request Forgery
medium
The EmbedPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.3. This is due to missing nonce validation on the clicked() function. This makes it possible for unauthenticated attackers to trigger notice clicks via a forged request granted they can trick a site adm...
- CVSS:
- 4.3
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- Sep 7, 2023
CVE-2023-51375 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.8.4
unknown
The EmbedPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.3. This is due to missing nonce validation on the clicked() function. This makes it possible for unauthenticated attackers to trigger notice clicks via a forged request granted they can trick a site adm...
- Affected:
- up to 3.8.4
- Fixed in:
- 3.8.4
- Disclosed:
- Sep 7, 2023
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.8.3
unknown
[en] The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributo...
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.3
- Disclosed:
- Aug 10, 2023
CVE-2023-4283 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.8.3
unknown
[en] The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2. This makes it possible for authenticated attackers with subscriber privileges or above, to delete...
- Affected:
- up to 3.8.3
- Fixed in:
- 3.8.3
- Disclosed:
- Aug 10, 2023
CVE-2023-4282 on NVD →
EmbedPress <= 3.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-lev...
- CVSS:
- 6.4
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Aug 9, 2023
CVE-2023-4283 on NVD →
EmbedPress <= 3.8.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Delete via admin_post_remove and remove_private_data
medium
The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2. This makes it possible for authenticated attackers with subscriber privileges or above, to delete plugi...
- CVSS:
- 5.4
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Aug 9, 2023
CVE-2023-4282 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.8.0
unknown
[en] The User Registration plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the pa...
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Jun 27, 2023
CVE-2023-3371 on NVD →
EmbedPress <= 3.7.3 - Sensitive Information Exposure
medium
The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the password prote...
- CVSS:
- 5.3
- Affected:
- up to 3.7.3
- Fixed in:
- 3.8.0
- Disclosed:
- Jun 26, 2023
CVE-2023-3371 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 2.0.3
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
CVE-2023-33999 on NVD →
EmbedPress – PDF Embedder, Embed PDF 3D FlipBook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Maps & Upload PDF Documents [embedpress] < 3.9.5
unknown
The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_source_data() and delete_source_data() functions in all version...
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.5