Description
The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.
Published: 2026-09-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in an insufficient authorization check on a Google Reviews REST API route in the EmbedPress WordPress plugin. Compromise allows a user with the Contributor role or higher to modify a site‑wide store, deleting legitimate reviews that an administrator has configured and injecting malicious or false content. These reviews are rendered publicly across the site, making the impact primarily the publication of unauthorized or misleading information.

Affected Systems

This flaw affects the EmbedPress plugin for WordPress versions 4.6.0 through 4.6.3. Users who have the Contributor role or greater, including administrators, are able to exploit the route. The plugin version 4.6.4 and later implements the necessary authorization checks and is not vulnerable.

Risk and Exploitability

The exact CVSS score is not provided, but the lack of serious exploitation evidence (no EPSS data) and its absence from the CISA KEV list suggest the risk of widespread exploitation is low at present. However, the authority bypass enables a high‑impact takeover of public content, giving an attacker a potential avenue to spread misinformation or disinformation. The attack vector requires only web‑based access to the affected site and sufficient WordPress role privileges, making it relatively simple for an attacker who can obtain a Contributor‑level account.

Generated by OpenCVE AI on September 5, 2026 at 07:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade EmbedPress to version 4.6.4 or later
  • Remove the EmbedPress plugin if it is not required for site functionality
  • Verify and restore any inadvertently deleted or corrupted Google review entries

Generated by OpenCVE AI on September 5, 2026 at 07:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.
Title EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-05T06:00:09.596Z

Reserved: 2026-09-02T16:09:02.492Z

Link: CVE-2026-84927

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T07:17:14.410

Modified: 2026-09-05T07:17:14.410

Link: CVE-2026-84927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T07:45:05Z

Weaknesses