---
id: CVE-2026-85002
title: >-
  The EmbedPress  WordPress plugin before 4.6.7 does not escape one of its block
  attributes before outputting it inside an HTML attribute, which could allow
  users with the contributor role and above to perform Stored Cross-Site
  Scripting a…
summary: >-
  The EmbedPress  WordPress plugin before 4.6.7 does not escape one of its block
  attributes before outputting it inside an HTML attribute, which could allow
  users with the contributor role and above to perform Stored Cross-Site
  Scripting a…
severity: none
cwe:
  - CWE-79
product: EmbedPress
affected:
  - EmbedPress < 4.6.7
published: '2026-09-27'
updated: '2026-09-27'
sourceUpdated: '2026-09-27T06:17:10.067'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85002'
references:
  - url: 'https://wpscan.com/vulnerability/ad155ea2-c804-4906-956e-e2da8050d0de/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-27T06:43:46.829Z'
---

## Overview

The EmbedPress  WordPress plugin before 4.6.7 does not escape one of its block attributes before outputting it inside an HTML attribute, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks against higher privileged users viewing the post.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
