Junglewise Threat Intelligence

CVE-2026-48872: EmbedPress sensitive data exposure via authorization bypass

CVE-2026-48872 · Severity: high · CVSS 7.5 · Published 2026-06-15

Technologies: WPDeveloper EmbedPress. Vendors: WPDeveloper.

Executive brief

EmbedPress is a WordPress plugin used to embed videos, maps, and other social media content into websites. A security flaw allows unauthenticated visitors to access sensitive information that should be restricted to site administrators. This exposure could lead to further attacks or the leakage of private configuration data, potentially compromising the entire website.

Technical details

EmbedPress versions 4.5.2 and earlier are vulnerable to sensitive data exposure due to an authorization bypass through a user-controlled key (CWE-639). The vulnerability allows a remote, unauthenticated attacker to access sensitive information by manipulating input parameters. This occurs because the plugin fails to properly validate the authorization of the requester before returning data. An attacker can exploit this over the network without any user interaction to gain access to restricted information. The issue is resolved in version 4.5.3.

Affected products

  • WPDeveloper EmbedPress <= 4.5.2

Timeline

  • 2026-05-07: other: Reported by Mukhlis Amien
  • 2026-06-01: patched: Version 4.5.3 released
  • 2026-06-15: disclosed: NVD publication date

References

Related threats