CVE · Medium

CVE-2023-5750 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 3.9.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-5750 EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 3.9.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.9.2 3.9.2 2023-11-17

CVE-2023-5750

The EmbedPress plugin for WordPress versions up to 3.9.1 contains a reflected cross-site scripting vulnerability in the hash parameter caused by inadequate sanitization and escaping of user input. An unauthenticated attacker could exploit this flaw by crafting a malicious link that, when clicked by a user, would execute arbitrary JavaScript code in the victim's browser. The vulnerability affects all versions prior to 3.9.2, where the issue has been patched.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.