CVE WATCH / VULNERABILITY DETAIL

CVE-2026-85001

MEDIUMCVSS 6.8NVD feed

Published 30 September 2026 · tracked since 30 September 2026

Description

The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-85001 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-85001

MEDIUMCVSS 6.8NVD feed

Published 30 September 2026 · tracked since 30 September 2026

Description

The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]