CVE-2026-66590: WordPress Tagembed plugin <= 7.4 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Tagembed Pluginto a version that resolves this vulnerability.Fixed in 7.5
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or other prior authentication. Exploitation requires user interaction, as indicated by the UI:R attack vector.
What impact could successful exploitation have?
The CVSS vector indicates low impact to confidentiality, integrity, and availability, with scope changed. Because this is an XSS issue, the practical impact depends on a victim interacting with attacker-controlled script content.
Which plugin versions are affected?
Tagembed plugin versions 7.4 and earlier are affected. The provided information does not identify a fixed version.