Reflected Cross-Site Scripting Vulnerability in EmbedPress Plugin for WordPress
CVE-2026-89330
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-89330?
The EmbedPress plugin, which enables the embedding of PDF documents and various media types on WordPress sites, is susceptible to reflected cross-site scripting through the 'unique' parameter across all versions up to 4.6.5. This flaw arises from insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary scripts into web pages. If a user is tricked into clicking a malicious link, the injected scripts may execute within their browser. This vulnerability is particularly concerning as it represents a regression from prior secure coding practices, such as the removal of the 'esc_url()' function that had previously mitigated similar issues. Consequently, it underscores the importance of maintaining robust security measures within the plugin ecosystem.
Affected Version(s)
EmbedPress β PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents 0 <= 4.6.5