Impact
The flaw in the EmbedPress plugin allows anyone on the internet to trigger the site’s Google Reviews API calls using the site’s own API key, forcing the site to incur billing charges without authorization. The same action also creates unlimited database entries, causing possible storage exhaustion and data integrity problems. This vulnerability highlights improper access control and unchecked data creation, giving an attacker full control over the site’s external API usage.
Affected Systems
The vulnerability is present in EmbedPress WordPress plugin versions 4.6.0 through 4.6.3. Versions 4.6.4 and later contain the fix.
Risk and Exploitability
There is no EPSS data, and the vulnerability is not listed in the KEV catalog, suggesting it has not yet been widely exploited. However, because the flaw permits unauthenticated public requests, an attacker can easily trigger API calls by simply visiting a crafted URL on the vulnerable site. The lack of authorization checks and the ability to create an unbounded number of database rows make the attack trivial and scalable, increasing the risk of both economic impact from third‑party API usage and system degradation from excessive data growth.
OpenCVE Enrichment