CVE-2026-48872: WordPress EmbedPress plugin <= 4.5.2 - Sensitive Data Exposure vulnerability
Published Jun 15, 2026
·Updated
Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
Affected Software
1 affected component
EmbedPress EmbedPress WordPress plugin<=4.5.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/embedpressto a version that resolves this vulnerability.Fixed in 4.5.3
Event History
Jun 15, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-48872?
The severity of CVE-2026-48872 is rated as high with a score of 7.5.
2
What does CVE-2026-48872 expose?
CVE-2026-48872 exposes sensitive data due to unauthenticated access in the EmbedPress plugin.
3
How do I fix CVE-2026-48872?
To fix CVE-2026-48872, you should update the EmbedPress plugin to version 4.5.3 or later.
4
Who is affected by CVE-2026-48872?
Any users of the EmbedPress WordPress plugin version 4.5.2 or earlier are affected by CVE-2026-48872.
5
Is CVE-2026-48872 a critical vulnerability?
CVE-2026-48872 is considered a high-risk vulnerability due to its potential for sensitive data exposure.