VendorsWPDeveloperembedpressany version
Vulnerabilities

WPDeveloper EmbedPress any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2024-43328
WordPress EmbedPress plugin <= 4.0.9 - Local File Inclusion vulnerability
Published 2024-08-19 · Analyzed
9.8EPSS 0.005
CVE-2024-31284
WordPress EmbedPress plugin <= 3.9.8 - Broken Access Control vulnerability
Published 2024-06-09 · Modified
9.8EPSS 0.004
CVE-2024-38707
WordPress EmbedPress plugin <= 4.0.4 - Broken Access Control vulnerability
Published 2024-11-01 · Analyzed
8.8EPSS 0.004
CVE-2023-51375
WordPress EmbedPress plugin <= 3.8.3 - Broken Access Control vulnerability
Published 2024-06-21 · Modified
8.8EPSS 0.003
CVE-2023-3371
EmbedPress <= 3.7.3 - Sensitive Information Exposure
Published 2023-06-27 · Modified
7.5EPSS 0.005
CVE-2024-43936
WordPress EmbedPress plugin <= 4.0.8 - Cross Site Scripting (XSS) vulnerability
Published 2024-08-29 · Analyzed
6.5EPSS 0.003
CVE-2024-50461
WordPress EmbedPress plugin <= 4.0.14 - Cross Site Scripting (XSS) vulnerability
Published 2024-10-28 · Modified
6.5EPSS 0.002
CVE-2024-1425
EmbedPress <= 3.9.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via Google Calendar Widget Link
Published 2024-02-20 · Modified
6.4EPSS 0.005
CVE-2023-4283
EmbedPress <= 3.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2023-08-10 · Modified
6.4EPSS 0.005
CVE-2024-3244
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-04-09 · Modified
6.4EPSS 0.005
CVE-2024-1349
EmbedPress <= 3.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-02-20 · Modified
6.4EPSS 0.004
CVE-2023-6986
EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-01-03 · Modified
6.4EPSS 0.004
CVE-2024-2128
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget
Published 2024-03-07 · Modified
6.4EPSS 0.004
CVE-2024-11203
EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name'
Published 2024-11-28 · Analyzed
6.4EPSS 0.004
CVE-2024-1565
EmbedPress <= 3.9.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via PDF Widget URL
Published 2024-06-13 · Modified
6.4EPSS 0.003
CVE-2024-2468
EmbedPress <= 3.9.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Attribute
Published 2024-03-23 · Modified
6.4EPSS 0.003
CVE-2024-4316
EmbedPress Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
Published 2024-05-09 · Modified
6.4EPSS 0.003
CVE-2024-1802
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block
Published 2024-03-07 · Modified
6.4EPSS 0.003
CVE-2024-3245
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block
Published 2024-04-06 · Modified
6.4EPSS 0.003
CVE-2024-5571
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget
Published 2024-06-05 · Modified
6.4EPSS 0.003
CVE-2023-5749
EmbedPress < 3.9.2 - Reflected XSS
Published 2023-12-11 · Modified
6.1EPSS 0.006
CVE-2023-5750
EmbedPress < 3.9.2 - Reflected XSS
Published 2023-12-11 · Modified
6.1EPSS 0.005
CVE-2023-4282
EmbedPress <= 3.8.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Delete via admin_post_remove and remove_private_data
Published 2023-08-10 · Modified
5.4EPSS 0.005
CVE-2024-2688
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Authenticated (Contributor+) Stored Cross-site Scripting via 'embedpress_doc_custom_color'
Published 2024-03-23 · Modified
5.4EPSS 0.003
CVE-2024-31274
WordPress EmbedPress plugin <= 3.9.11 - Broken Access Control vulnerability
Published 2024-06-09 · Modified
5.3EPSS 0.003
CVE-2024-1803
EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Insufficient Authorization Checks to Block Usual
Published 2024-05-23 · Modified
4.3EPSS 0.003