CVE-2026-85001 PUBLISHED

EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute

Assigner: WPScan
Reserved: 02.09.2026 Published: 30.09.2026 Updated: 30.09.2026

The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.

Product Status

Vendor Unknown
Product EmbedPress
Versions Default: unaffected
  • affected from 4.4.9 to 4.6.7 (excl.)

Credits

  • Revanth Hari Narayana Matte finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE