CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-61961HIGH | WordPress EmbedPress plugin <= 4.5.6 - Cross Site Scripting (XSS) vulnerabilityUnauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions. CWE-79Aug 6, 2026 | CVSS7.1v3.1 | EPSS0.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-48872HIGH | WordPress EmbedPress plugin <= 4.5.2 - Sensitive Data Exposure vulnerabilityUnauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions. CWE-639Jun 15, 2026 | CVSS7.5v3.1 | EPSS0.346% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38707MEDIUM | WordPress EmbedPress plugin <= 4.0.4 - Broken Access Control vulnerabilityMissing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a through 4.0.4. CWE-862Nov 1, 2024 | CVSS6.3v3.1 | EPSS0.42% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-50461MEDIUM | WordPress EmbedPress plugin <= 4.0.14 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper EmbedPress embedpress allows Stored XSS.This issue affects EmbedPress: from n/a through <= 4.0.14. CWE-79Oct 28, 2024 | CVSS6.5v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43936MEDIUM | WordPress EmbedPress plugin <= 4.0.8 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.8. CWE-79Aug 29, 2024 | CVSS6.5v3.1 | EPSS0.295% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-43328HIGH | WordPress EmbedPress plugin <= 4.0.9 - Local File Inclusion vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9. CWE-22Aug 19, 2024 | CVSS8.3v3.1 | EPSS0.498% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-51375MEDIUM | WordPress EmbedPress plugin <= 3.8.3 - Broken Access Control vulnerabilityMissing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3. CWE-862Jun 21, 2024 | CVSS4.3v3.1 | EPSS0.323% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-31284MEDIUM | WordPress EmbedPress plugin <= 3.9.8 - Broken Access Control vulnerabilityMissing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8. CWE-862Jun 9, 2024 | CVSS6.5v3.1 | EPSS0.397% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-31274MEDIUM | WordPress EmbedPress plugin <= 3.9.11 - Broken Access Control vulnerabilityMissing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.11. CWE-862Jun 9, 2024 | CVSS5.3v3.1 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |