Arbitrary Web Script Injection in EmbedPress Plugin for WordPress
CVE-2026-85001
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 30 September 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-85001?
The EmbedPress plugin for WordPress, prior to version 4.6.7, exhibits a security flaw where it fails to properly sanitize and escape an Elementor widget setting. This oversight allows users with Contributor roles or higher to execute arbitrary web scripts through HTML attributes. When affected content is viewed, this could lead to the execution of malicious scripts, potentially compromising site security and user data.
Affected Version(s)
EmbedPress 4.4.9 < 4.6.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.