Tagembed: Social Media Feeds and Customer Reviews Widget <= 7.4 - Unauthenticated Stored Cross-Site Scripting
high
The Tagembed: Social Media Feeds and Customer Reviews Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...
- CVSS:
- 7.2
- Affected:
- up to 7.4
- Fixed in:
- 7.5
- Disclosed:
- Aug 19, 2026
CVE-2026-66590 on NVD →
Tagembed <= 5.8 - Missing Authorization
medium
The Tagembed plugin for WordPress is vulnerable to unauthorized access of functionality in versions up to, and including, 5.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to invoke such functionality. The security impact is low.
- CVSS:
- 4.3
- Affected:
- up to 5.8
- Fixed in:
- 5.9
- Disclosed:
- May 17, 2024
CVE-2024-34804 on NVD →
Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds <= 4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...
- CVSS:
- 6.4
- Affected:
- up to 4.8
- Fixed in:
- 4.9
- Disclosed:
- Apr 16, 2024
CVE-2024-32561 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database