Impact
The vulnerability lies in an insufficient authorization check on a Google Reviews REST API route in the EmbedPress WordPress plugin. Compromise allows a user with the Contributor role or higher to modify a site‑wide store, deleting legitimate reviews that an administrator has configured and injecting malicious or false content. These reviews are rendered publicly across the site, making the impact primarily the publication of unauthorized or misleading information.
Affected Systems
This flaw affects the EmbedPress plugin for WordPress versions 4.6.0 through 4.6.3. Users who have the Contributor role or greater, including administrators, are able to exploit the route. The plugin version 4.6.4 and later implements the necessary authorization checks and is not vulnerable.
Risk and Exploitability
The exact CVSS score is not provided, but the lack of serious exploitation evidence (no EPSS data) and its absence from the CISA KEV list suggest the risk of widespread exploitation is low at present. However, the authority bypass enables a high‑impact takeover of public content, giving an attacker a potential avenue to spread misinformation or disinformation. The attack vector requires only web‑based access to the affected site and sufficient WordPress role privileges, making it relatively simple for an attacker who can obtain a Contributor‑level account.
OpenCVE Enrichment