CVE

CVE-2026-10526 — EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-10526 EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.6.1 Server-Side Request Forgery (SSRF) Unknown < 4.6.1 4.6.1 2026-08-04

CVE-2026-10526

The EmbedPress plugin for WordPress prior to version 4.6.1 fails to properly verify URLs submitted by users before initiating server-side communications, enabling unauthorized parties to coerce the site into sending HTTP requests to internal network locations that are not accounted for in WordPress's standard URL validation mechanisms. This vulnerability allows attackers to exploit a blind Server-Side Request Forgery flaw. Affected sites may inadvertently expose sensitive information or services to malicious actors.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.