Stored Cross-Site Scripting in Embed Any Document Plugin for WordPress
CVE-2026-18558

6.4MEDIUM

What is CVE-2026-18558?

The Embed Any Document plugin for WordPress is susceptible to stored cross-site scripting, allowing authenticated users with contributor-level access or higher to exploit the 'embeddoc' shortcode. Due to inadequate input sanitization and output escaping, attackers can inject hostile web scripts into pages, which are executed when users access those pages. This vulnerability affects all versions up to and including 2.7.13, posing a significant risk to website security and user data.

Affected Version(s)

Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files 0 <= 2.7.13

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Deva Parekh
.