Impact
The flaw in the EmbedPress plugin allows anyone on the internet to trigger the site’s Google Reviews API calls using the site’s own API key, causing unexpected billing charges. In addition, the same request creates unlimited attacker-controlled rows in the database, which can lead to storage exhaustion and data integrity problems. The weakness is an improper authorization check for a public review‑loading action, permitting unauthenticated users to exercise these abilities.
Affected Systems
This vulnerability is present in EmbedPress WordPress plugin versions 4.6.0 through 4.6.3. Versions 4.6.4 and later include the fix for the missing authorization guard.
Risk and Exploitability
The EPSS score is <1%, indicating a very low likelihood of exploitation, while the CVSS score of 5.3 reflects moderate risk. The vulnerability is not listed in the CISA KEV catalog. Because unauthenticated users can trigger the API calls by simply accessing a crafted URL, the attack is trivial to execute. The alternative effect of unbounded database row creation increases the risk of economic damage from third‑party API usage and potential service degradation from excessive data growth.
OpenCVE Enrichment