Input validation vulnerability in EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor 4.0.1

A plugin called EmbedPress used in WordPress websites has a security issue that allows attackers to input harmful web scripts. This can be done through the ‘url’ attribute in the EmbedPress PDF widget, which is not properly checked for safety. As a result, anyone with contributor-level access or higher can insert these scripts into pages, causing them to run whenever a user visits the page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.