plugin

Tagembed Widget Vulnerabilities

3 known security issues reported for the Tagembed Widget WordPress plugin. Most recent disclosed Aug 19, 2026.

1 high 2 medium

Running Tagembed Widget on your site? Check whether your installed version is affected.

Scan your site free

Tagembed: Social Media Feeds and Customer Reviews Widget <= 7.4 - Unauthenticated Stored Cross-Site Scripting

high

The Tagembed: Social Media Feeds and Customer Reviews Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.4. This is due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scrip...

CVSS:
7.2
Affected:
up to 7.4
Fixed in:
7.5
Disclosed:
Aug 19, 2026

CVE-2026-66590 on NVD →

Tagembed <= 5.8 - Missing Authorization

medium

The Tagembed plugin for WordPress is vulnerable to unauthorized access of functionality in versions up to, and including, 5.8. This makes it possible for authenticated attackers, with subscriber-level access and above, to invoke such functionality. The security impact is low.

CVSS:
4.3
Affected:
up to 5.8
Fixed in:
5.9
Disclosed:
May 17, 2024

CVE-2024-34804 on NVD →

Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds <= 4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it p...

CVSS:
6.4
Affected:
up to 4.8
Fixed in:
4.9
Disclosed:
Apr 16, 2024

CVE-2024-32561 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database