Stored XSS Vulnerability in Code Embed WordPress Plugin by Dartiss
CVE-2026-48093

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 August 2026

What is CVE-2026-48093?

The Code Embed WordPress plugin versions before 2.6.1 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability via its external URL embed feature. The vulnerability occurs when the plugin processes URL embed tokens contained in post content. An attacker can exploit this flaw by crafting a seemingly harmless URL that, when evaluated by an Administrator or Editor during the preview or review phase of a post, can execute malicious JavaScript. The lack of output sanitization and insufficient capability checks exacerbate the risk. This issue is distinct from previous vulnerabilities and has been addressed in the 2.6.1 update.

Affected Version(s)

code-embed < 2.6.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.