Stored XSS Vulnerability in Code Embed WordPress Plugin by Dartiss
CVE-2026-48093
6.5MEDIUM
What is CVE-2026-48093?
The Code Embed WordPress plugin versions before 2.6.1 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability via its external URL embed feature. The vulnerability occurs when the plugin processes URL embed tokens contained in post content. An attacker can exploit this flaw by crafting a seemingly harmless URL that, when evaluated by an Administrator or Editor during the preview or review phase of a post, can execute malicious JavaScript. The lack of output sanitization and insufficient capability checks exacerbate the risk. This issue is distinct from previous vulnerabilities and has been addressed in the 2.6.1 update.
Affected Version(s)
code-embed < 2.6.1