CVE WATCH / VULNERABILITY DETAIL

CVE-2026-85002

UNKNOWNCVSS 0NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-85002 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-85002

UNKNOWNCVSS 0NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]