Executive brief
Tagembed is a WordPress plugin that embeds social media content on websites. An unauthenticated attacker can inject malicious JavaScript code that executes in the browsers of visitors, potentially stealing session cookies, account credentials, or performing unauthorized actions on their behalf. The vulnerability requires user interaction (e.g., clicking a malicious link) but no special privileges to exploit.
Technical details
The vulnerability is an unauthenticated cross-site scripting (XSS) flaw in Tagembed plugin versions 7.4 and earlier. The root cause involves insufficient input validation or output encoding, allowing an attacker to inject malicious scripts that are reflected or stored and executed in victim browsers. Attack vector is network-based and requires user interaction (clicking a link or visiting a crafted page). An authenticated or unauthenticated attacker can inject scripts that steal session data, hijack accounts, or perform actions with visitor privileges. The vulnerability is patched in version 7.5 and later.
Affected products
- Tagembed Tagembed 7.4 and earlier
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Version 7.5 released as patch