Skip to main content

Vendor/product archive

wpdeveloper / embedpress CVEs

Beta · best-effort

26 CVEs tagged to wpdeveloper / embedpress0 Critical, 1 High, 25 Medium, 0 Low, 0 Unrated.

CVE-2024-11203

Published Nov 28, 2024

The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulne…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38707

Published Nov 1, 2024

Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a throu…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50461

Published Oct 28, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper EmbedPress embedpress allows Stored XSS.This issue affects EmbedP…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43936

Published Aug 29, 2024

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43328

Published Aug 19, 2024

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPres…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51375

Published Jun 21, 2024

Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1565

Published Jun 13, 2024

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Si…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31284

Published Jun 9, 2024

Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31274

Published Jun 9, 2024

Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.11.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5571

Published Jun 5, 2024

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Sto…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1803

Published May 23, 2024

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to una…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4316

Published May 14, 2024

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Sto…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3244

Published Apr 9, 2024

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Sto…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3245

Published Apr 6, 2024

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Sto…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2688

Published Mar 23, 2024

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Sto…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2468

Published Mar 23, 2024

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Sto…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1802

Published Mar 7, 2024

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Sto…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2128

Published Mar 7, 2024

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Sto…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1425

Published Feb 29, 2024

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Si…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1349

Published Feb 29, 2024

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Si…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6986

Published Jan 3, 2024

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Si…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-5750

Published Dec 11, 2023

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected C…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5749

Published Dec 11, 2023

The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape user input before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4283

Published Aug 10, 2023

The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficien…

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4282

Published Aug 10, 2023

The EmbedPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'admin_post_remove' and 'remove_private_data' functions in…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2