Vulnerabilities (CVE)

Filtered by vendor Wpdeveloper Subscribe
Filtered by product Embedpress
Total 26 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-5750 1 Wpdeveloper 1 Embedpress 2026-06-17 N/A 6.1 MEDIUM
The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-5749 1 Wpdeveloper 1 Embedpress 2026-06-17 N/A 6.1 MEDIUM
The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-51375 1 Wpdeveloper 1 Embedpress 2026-06-17 N/A 4.3 MEDIUM
Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.
CVE-2023-4283 1 Wpdeveloper 1 Embedpress 2026-06-17 N/A 6.4 MEDIUM
The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-4282 1 Wpdeveloper 1 Embedpress 2026-06-17 N/A 5.4 MEDIUM
The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in versions up to, and including, 3.8.2. This makes it possible for authenticated attackers with subscriber privileges or above, to delete plugin settings.
CVE-2023-3371 1 Wpdeveloper 1 Embedpress 2026-06-17 N/A 5.3 MEDIUM
The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' function in versions up to, and including, 3.7.3. This makes it possible for unauthenticated attackers to decrypt and view the password protected content.