Embed Bokun

Embed Bokun has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Embed Bokun has a vendor fix available, so running the current release closes it.

All of these findings were reported by Peter Thaleikis. Embed Bokun is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Embed Bokun vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-6221

Embed Bokun <= 0.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Parameter

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv0.24

Embed Bokun

luuptek

Author

luuptek

0.0(0)
0/100
Last Updated
2025-08-16 (1y ago)
Active Installs
100+
Downloads
4,436
Requires WP
5.0+
Requires PHP
5.6+
Tested up to
WP 6.8.8
Created
2020-01-22 (7y ago)

Embed Bokun allows to you add Bokun products to your website via Gutenberg blocks. To be able to use the plugin, you need to have Gutenberg active (WordPress version 5.0 and higher and classic editor not installed). Plugin is extreme developer friendly allowing to create custom Bokun product block via few actions and filters. More details and documentation about the plugin can be found from Github: https://github.com/luuptek/embed-bokun

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C