wpdevteam Vulnerabilities and Affected Products
Vulnerabilities associated with EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more.
Products
Clear product- Essential Addons for Elementor – Popular Elementor Templates & Widgets49 vulnerabilities
- Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns22 vulnerabilities
- EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more17 vulnerabilities
- BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor5 vulnerabilities
- NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar5 vulnerabilities
- BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot2 vulnerabilities
- Essential Blocks Pro2 vulnerabilities
- EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more1 vulnerability
- SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher1 vulnerability
- Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-7796MEDIUM | EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' AttributeThe EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block 'url' attribute in all versions up to, and including, 4.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page CWE-79Jun 6, 2026 | CVSS6.4v3.1 | EPSS0.331% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |