Stored Cross-Site Scripting in Embed Any Document Plugin for WordPress
CVE-2026-18558
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-18558?
The Embed Any Document plugin for WordPress is susceptible to stored cross-site scripting, allowing authenticated users with contributor-level access or higher to exploit the 'embeddoc' shortcode. Due to inadequate input sanitization and output escaping, attackers can inject hostile web scripts into pages, which are executed when users access those pages. This vulnerability affects all versions up to and including 2.7.13, posing a significant risk to website security and user data.
Affected Version(s)
Embed Any Document β Embed PDF, Word, PowerPoint and Excel Files 0 <= 2.7.13