Stored Cross-Site Scripting Vulnerability in EmbedPress Plugin for WordPress
CVE-2026-92727
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-92727?
The EmbedPress plugin for WordPress is susceptible to Stored Cross-Site Scripting attacks due to inadequate input sanitization and output escaping in the 'slidesShow' Block Attribute. Authenticated users with contributor-level access or higher can exploit this vulnerability to inject malicious web scripts into pages. The vulnerability is facilitated by the way the slidesShow block attribute interacts with an unquoted data-carousel-options HTML attribute. This flaw permits attack vectors that can break out of attribute constraints, enabling the injection of additional event handlers into the document object model, posing significant security risks for users visiting compromised pages.
Affected Version(s)
EmbedPress β PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents 0 <= 4.6.6