What is CVE-2026-61961?
An unauthenticated Cross Site Scripting (XSS) vulnerability has been identified in EmbedPress versions up to 4.5.6. This could allow an attacker to steal user data. Updating the plugin to the latest version is recommended.
Azərbaycanca: EmbedPress plaginində 4.5.6 versiyasına qədər autentifikasiya olmadan Cross Site Scripting (XSS) zəifliyi aşkar edilib. Bu, təcavüzkara istifadəçi məlumatlarını ələ keçirməyə imkan verə bilər. Plugin-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What are the affected versions of the EmbedPress plugin for the unauthenticated XSS vulnerability?
All versions of EmbedPress up to 4.5.6 are affected by this vulnerability.
What should I do to protect against CVE-2026-61961?
It is recommended to update the EmbedPress plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.