CVE-2023-51375 MEDIUM

CVE-2023-51375: WordPress EmbedPress plugin <= 3.8.3 - Broken Access Control vulnerability

Vendor Wpdeveloper
Product EmbedPress
Weakness CWE-862 · Missing authorization
Published June 21, 2024
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.8.3.

Explanation of Vulnerability in Simple Terms

02Summary

EmbedPress versions up to 3.8.3 lack proper authorization checks, allowing authenticated users with low privileges to modify content they should not have access to. The vulnerability requires a valid WordPress account but no special interaction. Site administrators should update to version 4.5.6 or later to prevent unauthorized content changes.

What an attacker can do

03Attacker Capabilities

Modify content or settings they lack permission to change.

Potential impact on your site

04Site Impact

Unauthorized users can alter site content, potentially defacing pages or injecting malicious material.

Conditions required to exploit

05Prerequisites

Attacker must have a valid WordPress user account with low-level privileges.

Key dates

06Disclosure timeline

June 21, 2024 CVE published
April 28, 2026 Record updated