Sceawere

Vulnerability Detail

CVE-2026-85002UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

EmbedPress Stored Cross-Site Scripting

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
1d ago
Vendor
Unknown
Product
EmbedPress
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The EmbedPress WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-09-27T06:17:10.067Z",
  "pubdate": "2026-09-27T06:17:10.067Z",
  "executiveSummary": "The EmbedPress WordPress plugin prior to version 4.6.7 contains a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from the improper sanitization and escaping of specific block attributes before they are rendered within HTML output.\nThe vulnerability allows an authenticated attacker with at least a contributor-level role to inject malicious JavaScript into block attributes. When a user with higher administrative privileges views the compromised post or page, the injected payload executes within the victim's browser session.\nThe impact of this vulnerability includes potential session hijacking, unauthorized actions performed on behalf of the administrator, and the exfiltration of sensitive site data. Because the exploit occurs in the context of the administrative interface, the risk is classified as significant. Exploitation requires authenticated access to the post editor but does not require additional complex configuration or external interaction beyond visiting the affected post.\nOrganizations using EmbedPress are advised to update to version 4.6.7 or later immediately to remediate the underlying sanitization flaw.",
  "technicalDetails": "The vulnerability resides in the EmbedPress block rendering mechanism, specifically where block attributes are processed and inserted into the document object model (DOM) without adequate output escaping. The root cause is the failure to apply context-aware encoding functions, such as esc_attr(), to data retrieved from the block attributes before embedding them into HTML attributes.\nAn attacker with the 'contributor' role possesses sufficient privileges to create or edit posts. By manipulating the block attributes provided to the EmbedPress plugin, an attacker can insert a malicious payload designed to break out of the intended HTML attribute context. For instance, an attribute intended for a URL or a configuration string can be crafted to include closing quotes and event handlers, such as 'onmouseover' or 'onerror', effectively injecting arbitrary JavaScript.\nThe attack flow begins when the contributor crafts a post containing a malicious EmbedPress block. Upon saving the post, the unsanitized payload is stored in the WordPress database as part of the post content. When an administrator or editor accesses the post via the WordPress dashboard, the server processes the post content and renders the malicious block. The server-side rendering logic inserts the unescaped attribute directly into the HTML output. Consequently, the victim's browser interprets the malicious attribute as an executable script, triggering the XSS.\nBecause the payload executes within the authenticated session of the privileged user, the attacker can leverage the victim's active session to perform administrative tasks. This includes creating new administrative accounts, modifying site settings, or installing malicious plugins. Furthermore, if the victim has high-level permissions, the script could potentially access sensitive information stored in the dashboard or perform cross-site request forgery (CSRF) actions against other endpoints. The vulnerability is restricted to users with at least 'contributor' access, meaning it is not exploitable by unauthenticated remote attackers. The flaw is present in all EmbedPress versions prior to 4.6.7, specifically within the components responsible for handling block attribute serialization and rendering."
}
CVE-2026-85002: EmbedPress Stored Cross-Site Scripting (MEDIUM Severity, CVSS: 6.8) | Sceawere