CVE-2026-85002
Received Received - Intake

Stored XSS in EmbedPress WordPress Plugin

Vulnerability report for CVE-2026-85002, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: WPScan

Description

The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
embedpress embedpress to 4.6.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the WordPress plugin EmbedPress versions before 4.6.7. It occurs because the plugin does not escape a block attribute before outputting it in an HTML attribute. This allows users with contributor roles or higher to inject malicious scripts that execute when higher-privileged users view the post.

Detection Guidance

To detect this vulnerability, check the version of the EmbedPress plugin installed on your WordPress site. If the version is below 4.6.7, the site is vulnerable. You can verify the version by inspecting the plugin files or using WordPress admin panel.

Impact Analysis

If exploited, this vulnerability could allow attackers to inject malicious scripts into your WordPress site. When higher-privileged users view the affected post, these scripts could execute, potentially leading to unauthorized actions, data theft, or further compromise of your site.

Compliance Impact

This vulnerability could impact compliance by potentially exposing user data through malicious script execution. GDPR requires protecting personal data, and HIPAA mandates safeguarding health information. A successful exploit may lead to data breaches, resulting in legal penalties or loss of trust.

Mitigation Strategies

Immediately update the EmbedPress plugin to version 4.6.7 or later. If updating is not possible, consider disabling the plugin temporarily until an update is applied. Regularly monitor for plugin updates and security advisories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85002. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart