在 EmbedPress WordPress 插件 4.6.7 版本之前,插件在将其某个区块属性输出到 HTML 属性之前未进行转义处理,这可能导致具有“贡献者”及以上角色的用户实施存储型跨站脚本攻击(Stored XSS),从而对查看该帖子的权限更高的用户造成危害。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | EmbedPress | 0 ~ 4.6.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89006 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Stored XSS via Feed Import | |
| CVE-2026-84069 | WebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.php | |
| CVE-2026-81655 | Ad Inserter 2.8.12 - 2.8.18 - Subscriber+ RCE / Stored XSS via Global Custom Fields | |
| CVE-2026-82841 | UpdraftPlus 1.23.8 - 1.26.7 - Subscriber+ Remote Storage Credential Disclosure via Migrati | |
| CVE-2026-86609 | Download Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock Subscription | |
| CVE-2026-86839 | Bookly < 28.3 - Staff+ Appointment and Payment Disclosure, Modification and Deletion via I | |
| CVE-2026-86841 | Bookly 23.2 - 28.2 - Bookly Administrator+ PHP Object Injection via Diagnostics Advanced O | |
| CVE-2026-89001 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ Post Publication and Author Spoofing vi | |
| CVE-2026-89003 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Preview | |
| CVE-2026-96899 | Optima Express 8.6.0 - 8.7.5 - Author+ Stored XSS via faq_script | |
| CVE-2026-89000 | WPeMatico RSS Feed Fetcher < 2.8.27 - Contributor+ SSRF via Campaign Run | |
| CVE-2026-96896 | Malcure Malware Shield < 19.9.7 - Multisite Subsite Admin+ Arbitrary File Write and Deleti | |
| CVE-2026-96897 | Optima Express 8.5.0 - 8.7.5 - Unauthenticated Author Account Creation & Application Passw | |
| CVE-2026-96895 | WP YouTube Lyte < 1.7.31 - Contributor+ Stored XSS via Embed Block Attributes | |
| CVE-2026-92995 | Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file | |
| CVE-2026-92436 | Mailchimp for WooCommerce < 6.3 - Unauthenticated Customer Email and Cart Disclosure via I | |
| CVE-2026-97319 | PowerPress < 11.17.2 - Contributor+ Stored XSS via Podcast Player Block | |
| CVE-2026-97227 | NextScripts: Social Networks Auto-Poster < 4.4.8 - Authenticated Social Account Credential |
No comments yet