Sceawere

Vulnerability Detail

CVE-2026-18558UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Embed Any Document Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
awsmin
Product
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embeddoc' shortcode in all versions up to, and including, 2.7.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T06:16:42.820Z",
  "pubdate": "2026-10-10T06:16:42.820Z",
  "executiveSummary": "The Embed Any Document plugin for WordPress, in versions up to and including 2.7.13, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from inadequate input sanitization and output escaping within the 'embeddoc' shortcode processing logic.\nThe vulnerability allows authenticated users with contributor-level privileges or higher to inject malicious JavaScript payloads into posts or pages. When these compromised pages are viewed by other users, including administrators, the injected script executes within the context of the victim's browser session. This can lead to unauthorized actions, such as session hijacking, redirection to malicious domains, or the exfiltration of sensitive information, including authentication tokens. Because the payload is stored persistently in the database, the attack is non-interactive and executes every time the affected content is rendered. Given the broad potential for impact, including complete site compromise if an administrator interacts with the payload, this vulnerability represents a significant security risk for WordPress installations utilizing this plugin.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the 'embeddoc' shortcode handler to correctly sanitize user-supplied attributes before they are rendered in the HTML output. WordPress shortcode attributes are often passed through parsers that may not account for malicious payload injection if the plugin fails to implement robust input validation and context-aware output escaping.\nThe attack flow initiates when an authenticated attacker with at least contributor-level access creates or edits a post or page containing the 'embeddoc' shortcode. The attacker embeds a crafted JavaScript payload within one of the shortcode attributes, such as the 'url' or a custom parameter processed by the plugin. Because the plugin does not adequately filter these inputs, the payload is persisted into the WordPress database as part of the post content.\nWhen a victim, such as a site administrator, loads the page containing the malicious shortcode, the server retrieves the stored post content and executes the plugin's shortcode rendering function. The unescaped payload is then reflected directly into the Document Object Model (DOM) of the victim's browser. Once rendered, the browser interprets the injected script as legitimate site content, allowing it to execute within the victim's origin.\nThe execution of the script allows the attacker to perform actions on behalf of the victim. If the victim has administrative privileges, the attacker could potentially create new administrative accounts, modify plugin configurations, or inject persistent backdoors into the theme files. This bypasses typical access controls because the malicious actions are performed via the authenticated session of the victim. The attack requires no social engineering, as the code executes automatically upon page load. The vulnerability is categorized as Stored XSS due to the persistence of the malicious script in the database. Successful exploitation relies entirely on the lack of proper output encoding in the plugin's shortcode rendering logic, which fails to neutralize executable tags or attributes, thereby permitting arbitrary JavaScript injection."
}
CVE-2026-18558: Embed Any Document Stored XSS (MEDIUM Severity, CVSS: 6.4) | Sceawere