CVE-2026-48093
Last modified
CVE-2026-48093 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches the remote URL, and inserts the remote response body into the page without output sanitization or an `unfiltered_html` capability check. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches the remote URL, and inserts the remote response body into the page without output sanitization or an `unfiltered_html` capability check. This allows a Contributor attacker to submit a pending post containing an inert-looking URL token that executes attacker-controlled JavaScript when an Administrator or Editor previews or reviews the post. This is distinct from CVE-2026-2512, which affected custom field meta values up to version 2.5.1. This vector affects version 2.6 and uses the documented external URL embed feature in post content. This particular issue is patched in version 2.6.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| dartiss | code-embed | < 2.6.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-48093?
How severe is CVE-2026-48093?
How do I fix CVE-2026-48093?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48088OpenReception's appointment booking software provides an end…9.4
- CVE-2026-48089DevGuard provides vulnerability management for the full soft…7.1
- CVE-2026-4809plank/laravel-mediable through version 6.4.0 can allow uploa…9.8
- CVE-2026-48090Envoy is an open source edge and service proxy designed for …5.9
- CVE-2026-48091Rejected reason: Further research determined the issue is no…
- CVE-2026-480927-Zip is a file archiver with a high compression ratio. Vers…8.1
- CVE-2026-48094The ShareOpenly WordPress plugin prior to version 1.2.1 cont…5.3
- CVE-2026-480957-Zip is a file archiver with a high compression ratio. Vers…8.8
- CVE-2026-48096OpenFGA is an authorization/permission engine built for deve…5.3
- CVE-2026-48097NexTor IP Changer is a command-line tool that leverages the …7.8
- CVE-2026-48098NexTor IP Changer is a command-line tool that leverages the …7.3
- CVE-2026-4810A Code Injection and Missing Authentication vulnerability in…9.3
Are you affected by CVE-2026-48093?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
