WPDeveloper / Embedpress
26 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-61961 | WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | Aug 6, 2026 |
| CVE-2026-48872 | WordPress EmbedPress plugin <= 4.5.2 - Sensitive Data Exposure vulnerability | HIGH | 7.5 | Jun 15, 2026 |
| CVE-2024-11203 | EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Au… | MEDIUM | 6.4 | Nov 28, 2024 |
| CVE-2024-38707 | WordPress EmbedPress plugin <= 4.0.4 - Broken Access Control vulnerability | HIGH | 8.8 | Nov 1, 2024 |
| CVE-2024-50461 | WordPress EmbedPress plugin <= 4.0.14 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | Oct 28, 2024 |
| CVE-2024-43936 | WordPress EmbedPress plugin <= 4.0.8 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | Aug 29, 2024 |
| CVE-2024-43328 | WordPress EmbedPress plugin <= 4.0.9 - Local File Inclusion vulnerability | CRITICAL | 9.8 | Aug 19, 2024 |
| CVE-2023-51375 | WordPress EmbedPress plugin <= 3.8.3 - Broken Access Control vulnerability | HIGH | 8.8 | Jun 21, 2024 |
| CVE-2024-1565 | EmbedPress <= 3.9.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via PDF Widget URL | MEDIUM | 6.4 | Jun 13, 2024 |
| CVE-2024-31284 | WordPress EmbedPress plugin <= 3.9.8 - Broken Access Control vulnerability | CRITICAL | 9.8 | Jun 9, 2024 |
| CVE-2024-31274 | WordPress EmbedPress plugin <= 3.9.11 - Broken Access Control vulnerability | MEDIUM | 5.3 | Jun 9, 2024 |
| CVE-2024-5571 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 4.0.1 - Authenticated… | MEDIUM | 6.4 | Jun 5, 2024 |
| CVE-2024-1803 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Insufficient… | MEDIUM | 4.3 | May 23, 2024 |
| CVE-2024-4316 | EmbedPress Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.16 - Authenticated (… | MEDIUM | 6.4 | May 9, 2024 |
| CVE-2024-3244 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated… | MEDIUM | 6.4 | Apr 9, 2024 |
| CVE-2024-3245 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated… | MEDIUM | 6.4 | Apr 6, 2024 |
| CVE-2024-2468 | EmbedPress <= 3.9.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Attribute | MEDIUM | 6.4 | Mar 23, 2024 |
| CVE-2024-2688 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Authenticated… | MEDIUM | 5.4 | Mar 23, 2024 |
| CVE-2024-1802 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated… | MEDIUM | 6.4 | Mar 7, 2024 |
| CVE-2024-2128 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated… | MEDIUM | 6.4 | Mar 7, 2024 |
| CVE-2024-1349 | EmbedPress <= 3.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | MEDIUM | 6.4 | Feb 20, 2024 |
| CVE-2024-1425 | EmbedPress <= 3.9.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via Google Calendar Widget Link | MEDIUM | 6.4 | Feb 20, 2024 |
| CVE-2023-6986 | EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor <= 3.9.5 - Authenticated (Contributor… | MEDIUM | 6.4 | Jan 3, 2024 |
| CVE-2023-5749 | EmbedPress < 3.9.2 - Reflected XSS | MEDIUM | 6.1 | Dec 11, 2023 |
| CVE-2023-5750 | EmbedPress < 3.9.2 - Reflected XSS | MEDIUM | 6.1 | Dec 11, 2023 |
Showing 1 to 25 of 26 CVEs