Impact
The EmbedPress WordPress plugin version 4.6.0 through 4.6.3 contains an insufficient authorization check on a Google Reviews REST API route, allowing a user with a Contributor role or higher to modify a site‑wide storage of reviews. The vulnerability permits deletion of reviews that an administrator has configured and the insertion of arbitrary content; these reviews are rendered publicly across the website, potentially delivering misleading or malicious information to visitors.
Affected Systems
This flaw affects the EmbedPress plugin for WordPress before version 4.6.4. Any WordPress installation utilizing the plugin in the 4.6.0 – 4.6.3 range and granting a Contributor or higher role to a user is vulnerable, as the lack of proper authorization on the REST endpoint can be exploited to alter reviews that display publicly.
Risk and Exploitability
The CVSS score of 2.7 indicates a low severity. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, pointing to a low likelihood of wide‑scale exploitation. The likely attack vector is a web‑based request to the vulnerable REST endpoint, requiring that the attacker possess a WordPress account with Contributor or higher privileges; based on the description, it is inferred that any user with those privileges can trigger the exploit without additional technical barriers.
OpenCVE Enrichment