CVE · Medium

CVE-2023-5749 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 3.9.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-5749 EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 3.9.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.9.2 3.9.2 2023-11-17

CVE-2023-5749

The EmbedPress plugin for WordPress prior to version 3.9.2 contains a reflected cross-site scripting vulnerability in the password parameter that affects all versions through 3.9.1. The flaw stems from inadequate sanitization of user input and failure to properly escape output, allowing unauthenticated attackers to inject malicious scripts that execute when users click a crafted link. This vulnerability can be exploited to run arbitrary code in the context of a victim's browser session.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.