Embedpress
Vendor:
First CVE: Jun 27, 2023 · Active for 3 years
27
Total CVEs
More Total CVEs than 96% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Embedpress over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2023
3 years ago
Most Recent CVE
Jun 15, 2026
39 days ago
CVE Severity & Scoring
Embedpress27 CVEs
78%
15%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (33.3%)
Unknown0 (0.0%)
Required18 (66.7%)
Privileges Required
Low20 (74.1%)
High0 (0.0%)
None7 (25.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43328CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress | Aug 19, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-31284CRITICAL Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8. | Jun 9, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-48872HIGH Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions. | Jun 15, 2026 | 7.5 | 26 | NO | NO |
CVE-2023-51375HIGH Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3. | Jun 21, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-38707HIGH Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a throug | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2023-3371HIGH The EmbedPress plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'lock_content_form_handler' and 'display_password_form' f | Jun 27, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-5750MEDIUM The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cr | Dec 11, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-4283MEDIUM The EmbedPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedpress_calendar' shortcode in versions up to, and including, 3.8.2 due to insufficient | Aug 10, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-5571MEDIUM The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stor | Jun 5, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-2688MEDIUM The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stor | Mar 23, 2024 | 5.4 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (27 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (27 CVEs).
Media Mentions
Signals from CVEs in this product scope (27 CVEs).
Top CNAs Publishing CVEs For Embedpress
Top CWEs
Versions
No cataloged versions.