What is CVE-2026-48093?
The Code Embed WordPress plugin before version 2.6.1 contains a stored Cross-Site Scripting (XSS) vulnerability via the external URL embed feature. An attacker can inject a malicious URL, causing the remote response body to be inserted into the page. Updating the plugin to version 2.6.1 or later is recommended.
Azərbaycanca: Code Embed WordPress plaginində (2.6.1-dən əvvəlki versiyalarda) xarici URL yerləşdirmə funksiyası vasitəsilə saxlanılmış Cross-Site Scripting (XSS) zəifliyi aşkarlanıb. Təcavüzkar zərərli URL daxil edərək uzaq serverdən gələn cavabı səhifəyə yeridə bilər. Plagini 2.6.1 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which feature of the Code Embed plugin is affected by CVE-2026-48093?
This vulnerability affects the plugin's external URL embed feature. An attacker can inject a malicious URL through this feature, causing the remote response body to be inserted into the page.
To which version should users upgrade to fix CVE-2026-48093?
It is recommended to update the Code Embed plugin to version 2.6.1 or later to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.