Input validation vulnerability in EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor 3.9.1

The EmbedPress plugin for WordPress has an issue which could allow malicious users to inject scripts into pages. This issue affects all versions of the plugin up to 3.9.1. The vulnerability is caused by a lack of protection against malicious input, and a failure to properly escape output. This means that if a user clicks a link without knowing it is malicious, scripts could be injected into the page and could be executed.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.