๐Ÿ” CVE Alert

CVE-2026-85001

UNKNOWN 0.0

EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.

Vendor unknown
Product embedpress
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown embedpress

Be the first to know when new unknown vulnerabilities affecting unknown embedpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / EmbedPress
4.4.9 < 4.6.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/889be882-342b-4331-89c5-9eebe90d3704/

Credits

Revanth Hari Narayana Matte WPScan