Wpdeveloper
Wpdeveloper Embedpress: vulnerabilidades y CVE
Wpdeveloper Embedpress tiene 36 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE36
Últimos 12 meses10
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85001 | Media (6.8) | 0.24% | — | 30 sept 2026 | The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to… |
| CVE-2026-85002 | Media (6.8) | 0.24% | — | 27 sept 2026 | The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored… |
| CVE-2026-89330 | Media (6.1) | 0.37% | — | 18 sept 2026 | The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'unique' parameter in all… |
| CVE-2026-84936 | Media (5.3) | 0.30% | — | 5 sept 2026 | The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests… |
| CVE-2026-84927 | Baja (2.7) | 0.28% | — | 5 sept 2026 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide… |
| CVE-2026-84926 | Baja (2.7) | 0.32% | — | 5 sept 2026 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read… |
| CVE-2026-61961 | Alta (7.1) | 0.25% | — | 6 ago 2026 | Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. |
| CVE-2026-10526 | Media (5.8) | 0.31% | — | 4 ago 2026 | The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site to send HTTP… |
| CVE-2026-48872 | Alta (7.5) | 0.39% | — | 15 jun 2026 | Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions. |
| CVE-2026-7796 | Media (6.4) | 0.42% | — | 6 jun 2026 | The EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in all versions up to,… |
| CVE-2024-11203 | Media (5.4) | 0.37% | — | 28 nov 2024 | The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… |
| CVE-2024-38707 | Alta (8.8) | 0.42% | — | 1 nov 2024 | Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a through 4.0.4. |
| CVE-2024-50461 | Media (5.4) | 0.25% | — | 28 oct 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper EmbedPress embedpress allows Stored XSS.This issue affects EmbedPress: from n/a through <= 4.0.14. |
| CVE-2024-43936 | Media (5.4) | 0.29% | — | 29 ago 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.8. |
| CVE-2024-43328 | Crítica (9.8) | 0.50% | — | 19 ago 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9. |
| CVE-2023-51375 | Alta (8.8) | 0.32% | — | 21 jun 2024 | Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3. |
| CVE-2024-1565 | Media (5.4) | 0.34% | — | 13 jun 2024 | The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the PDF Widget URL in… |
| CVE-2024-31284 | Crítica (9.8) | 0.40% | — | 9 jun 2024 | Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8. |
| CVE-2024-31274 | Media (5.3) | 0.34% | — | 9 jun 2024 | Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.11. |
| CVE-2024-5571 | Media (5.4) | 0.31% | — | 5 jun 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url'… |
| CVE-2024-1803 | Media (4.3) | 0.28% | — | 23 may 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to… |
| CVE-2024-4316 | Media (5.4) | 0.34% | — | 14 may 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’… |
| CVE-2024-3244 | Media (5.4) | 0.51% | — | 9 abr 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… |
| CVE-2024-3245 | Media (5.4) | 0.32% | — | 6 abr 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… |
| CVE-2024-2688 | Media (5.4) | 0.34% | — | 23 mar 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… |
| CVE-2024-2468 | Media (5.4) | 0.34% | — | 23 mar 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… |
| CVE-2024-1802 | Media (5.4) | 0.32% | — | 7 mar 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… |
| CVE-2024-2128 | Media (5.4) | 0.40% | — | 7 mar 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… |
| CVE-2024-1425 | Media (5.4) | 0.54% | — | 29 feb 2024 | The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Calendar… |
| CVE-2024-1349 | Media (5.4) | 0.44% | — | 29 feb 2024 | The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.