Impact
The EmbedPress WordPress plugin versions 4.6.0 through 4.6.3 allows any authenticated user with contributor or higher privileges to access a Google Reviews REST route that is not properly restricted. This route returns the site administrator’s email address, a piece of information normally withheld from non‑administrator roles by WordPress core. The flaw does not grant code execution or direct access to the file system; it merely exposes an administrative credential through a REST API endpoint.
Affected Systems
WordPress sites that have the EmbedPress plugin installed in any version prior to 4.6.4 are affected. Specifically, installers that used EmbedPress versions 4.6.0, 4.6.1, 4.6.2, or 4.6.3 expose the vulnerability. The issue is isolated to the plugin’s REST API handling and does not affect the underlying WordPress installation unless the same misconfiguration exists elsewhere.
Risk and Exploitability
The vulnerability requires only authenticated access, not elevated privileges beyond contributor level. An attacker can retrieve the administrator's email, facilitating phishing, credential-guessing, or social engineering attacks. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because the impact is limited to disclosure of a contact detail rather than system compromise, the risk is moderate, though the lack of a higher severity score means that it is still critical for sites that handle sensitive administration data.
OpenCVE Enrichment