CVE-2023-5750: EmbedPress < 3.9.2 - Reflected XSS
The EmbedPress WordPress plugin before 3.9.2 does not sanitise and escape a parameter before outputting it back in the page containing a specific content, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5750?
CVE-2023-5750 is classified as a high severity vulnerability due to its potential impact on high privilege users.
How do I fix CVE-2023-5750?
The issue in CVE-2023-5750 can be fixed by updating the EmbedPress WordPress plugin to version 3.9.2 or later.
What kind of vulnerability is CVE-2023-5750?
CVE-2023-5750 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the EmbedPress WordPress plugin.
Who is affected by CVE-2023-5750?
CVE-2023-5750 primarily affects high privilege users, such as admins, using the affected version of the EmbedPress plugin.
What versions of EmbedPress are vulnerable to CVE-2023-5750?
Versions of EmbedPress prior to 3.9.2 are vulnerable to CVE-2023-5750.