plugin

Simple Embed Code Vulnerabilities

10 known security issues reported for the Simple Embed Code WordPress plugin. Most recent disclosed Mar 19, 2026.

5 medium

Running Simple Embed Code on your site? Check whether your installed version is affected.

Scan your site free

Code Embed - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields vulnerability

medium

Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields vulnerability

CVSS:
6.5
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
Mar 19, 2026

Code Embed <= 2.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields

medium

The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field meta values in all versions up to, and including, 2.5.1. This is due to the plugin's sanitization function `sec_check_post_fields()` only running on the `save_post` hook, while WordPress allows custom fields to be added vi...

CVSS:
6.4
Affected:
up to 2.5.1
Fixed in:
2.5.2
Disclosed:
Mar 17, 2026

CVE-2026-2512 on NVD →

Code Embed [simple-embed-code] < 2.5.1

unknown

[en] The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the we...

Affected:
up to 2.5.1
Fixed in:
2.5.1
Disclosed:
Nov 9, 2024

CVE-2024-10814 on NVD →

Code Embed <= 2.5 - Authenticated (Contributor+) Server-Side Request Forgery

medium

The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web app...

CVSS:
6.4
Affected:
up to 2.5
Fixed in:
2.5.1
Disclosed:
Nov 8, 2024

CVE-2024-10814 on NVD →

Code Embed [simple-embed-code] < 2.5

unknown

[en] The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient restrictions on who can utilize the functionality. This makes it possible for authenticated attackers, with contributor-level ac...

Affected:
up to 2.5
Fixed in:
2.5
Disclosed:
Oct 4, 2024

CVE-2024-8804 on NVD →

Code Embed <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient restrictions on who can utilize the functionality. This makes it possible for authenticated attackers, with contributor-level access...

CVSS:
6.4
Affected:
up to 2.4
Fixed in:
2.5
Disclosed:
Oct 3, 2024

CVE-2024-8804 on NVD →

Code Embed [simple-embed-code] < 2.3.7

unknown

[en] Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a through 2.3.6.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Mar 21, 2024

CVE-2023-49837 on NVD →

Code Embed <= 2.3.6 - Authenticated(Contributor+) Denial of Service

medium

The Code Embed plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 2.3.6. This makes it possible for authenticated attackers, with contributor access and above, to disrupt access to the site.

CVSS:
6.5
Affected:
up to 2.3.6
Fixed in:
2.3.7
Disclosed:
Dec 5, 2023

CVE-2023-49837 on NVD →

Code Embed [simple-embed-code] < 2.0.2

unknown

This plugin is prone to a cross site scripting vulnerability in wp-admin/admin.php suffix parameter. Update the plugin.

Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Aug 1, 2014

Code Embed [simple-embed-code] < 2.0.2

unknown

The Code Embed WordPress plugin was affected by a wp-admin/admin.php suffix Parameter XSS security vulnerability.

Affected:
up to 2.0.2
Fixed in:
2.0.2

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database