CVE-2023-49837 MEDIUM

CVE-2023-49837: WordPress embed-code plugin <= 2.3.6 - Denial of Service Attack vulnerability

Vendor David Artiss
Product Code Embed
Weakness CWE-400
Published March 21, 2024
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

Uncontrolled Resource Consumption vulnerability in David Artiss Code Embed.This issue affects Code Embed: from n/a through 2.3.6.

Explanation of Vulnerability in Simple Terms

02Summary

Code Embed through version 2.3.6 does not properly limit resource consumption when processing embedded content. An authenticated user with low privileges can trigger excessive resource usage, causing the site to become slow or unresponsive. No code execution or data breach occurs, but availability is impacted.

What an attacker can do

03Attacker Capabilities

Make the site slow or unresponsive by consuming excessive server resources.

Potential impact on your site

04Site Impact

Site performance degradation or temporary unavailability during or after an attack.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege authenticated account; no user interaction required.

Key dates

06Disclosure timeline

March 21, 2024 CVE published
April 28, 2026 Record updated