Embed Bokun
Embed Bokun has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Embed Bokun has a vendor fix available, so running the current release closes it.
All of these findings were reported by Peter Thaleikis. Embed Bokun is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-6221Embed Bokun <= 0.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Parameter
Read the full analysisVulnerability Records
Embed Bokun
Author
luuptek
Embed Bokun allows to you add Bokun products to your website via Gutenberg blocks. To be able to use the plugin, you need to have Gutenberg active (WordPress version 5.0 and higher and classic editor not installed). Plugin is extreme developer friendly allowing to create custom Bokun product block via few actions and filters. More details and documentation about the plugin can be found from Github: https://github.com/luuptek/embed-bokun
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C