Cross-Site Scripting
21 records67.7%First: 2023. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 31 vulnerability records associated with EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents, published between 2023 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2023 | 8 | |
| 2024 | 21 | |
| 2026 | 2 |
| Severity | Records | Share |
|---|---|---|
| Critical | 1 | 3.2% |
| Medium | 30 | 96.8% |
First: 2023. Latest: 2026.
First: 2023. Latest: 2024.
First: 2023. Latest: 2026.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
4.5.44.5.34.1.44.1.04.0.94.0.104.0.54.0.23.9.134.0.33.9.173.9.153.9.123.9.113.9.93.9.63.9.53.9.23.8.43.8.32.0.33.8.0Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.5.3 | EmbedPress <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block 'url' Attribute | June 5, 2026 | 4.5.4 | Medium |
*-4.5.2 | EmbedPress – PDF Embedder, Embed PDF viewer, YouTube Videos, 3D FlipBook, Social feeds & more <= 4.5.2 - Unauthenticated Information Exposure | June 1, 2026 | 4.5.3 | Medium |
*-4.1.3 | EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name' | November 27, 2024 | 4.1.4 | Medium |
*-4.0.14 | EmbedPress <= 4.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting | October 24, 2024 | 4.1.0 | Medium |
*-4.0.8 | EmbedPress <= 4.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting | August 26, 2024 | 4.0.9 | Medium |
*-4.0.9 | EmbedPress <= 4.0.9 - Unauthenticated Local File Inclusion | August 16, 2024 | 4.0.10 | Critical |
*-4.0.4 | EmbedPress <= 4.0.4 - Missing Authorization | July 11, 2024 | 4.0.5 | Medium |
*-3.9.10 | EmbedPress <= 3.9.10 - Authenticated(Contributor+) Stored Cross-Site Scripting via PDF Widget URL | June 12, 2024 | 3.9.11 | Medium |
*-4.0.1 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget | June 4, 2024 | 4.0.2 | Medium |
*-3.9.12 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Insufficient Authorization Checks to Block Usual | May 22, 2024 | 3.9.13 | Medium |
*-4.0.2 | PDF.js < 4.2.67 - Arbitrary JavaScript Execution | May 20, 2024 | 4.0.3 | Medium |
*-3.9.16 | EmbedPress Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.16 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | May 9, 2024 | 3.9.17 | Medium |
*-3.9.8 | EmbedPress <= 3.9.8 - Missing Authorization via handle_calendly_data | April 5, 2024 | 3.9.9 | Medium |
*-3.9.14 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block | April 5, 2024 | 3.9.15 | Medium |
*-3.9.14 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | April 5, 2024 | 3.9.15 | Medium |
*-3.9.11 | EmbedPress <= 3.9.11 - Missing Authorization | April 5, 2024 | 3.9.12 | Medium |
*-3.9.12 | EmbedPress <= 3.9.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Attribute | March 22, 2024 | 3.9.13 | Medium |
*-3.9.12 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Authenticated (Contributor+) Stored Cross-site Scripting via 'embedpress_doc_custom_color' | March 22, 2024 | 3.9.13 | Medium |
*-3.9.10 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget | March 7, 2024 | 3.9.11 | Medium |
*-3.9.10 | EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block | March 7, 2024 | 3.9.11 | Medium |
*-3.9.8 | EmbedPress <= 3.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | February 14, 2024 | 3.9.9 | Medium |
*-3.9.8 | EmbedPress <= 3.9.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via Google Calendar Widget Link | February 14, 2024 | 3.9.9 | Medium |
[*, 3.9.5) | EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | January 2, 2024 | 3.9.6 | Medium |
[*, 3.9.5) | EmbedPress <= 3.9.4 - Missing Authorization | December 8, 2023 | 3.9.5 | Medium |
*-3.9.1 | EmbedPress <= 3.9.1 - Reflected Cross-Site Scripting | November 17, 2023 | 3.9.2 | Medium |
Selected source records
Published: June 5, 2026
Published: June 1, 2026
Published: November 27, 2024
Published: October 24, 2024
Published: August 26, 2024
Published: August 16, 2024
Published: July 11, 2024
Published: June 12, 2024
Published: August 16, 2024
Published: November 27, 2024
Published: May 9, 2024
Published: August 26, 2024
Published: March 7, 2024
Published: February 14, 2024
Published: March 7, 2024
Published: February 14, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.