๐Ÿ” CVE Alert

CVE-2025-10750

MEDIUM 5.3

PowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information Disclosure

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endpoint accessible via the mo_epbr_admin_observer() function hooked on 'init'. This makes it possible for unauthenticated attackers to access sensitive Azure AD user information including personal identifiable information (PII) such as displayName, mail, phones, department, or detailed OAuth error data including Azure AD Application/Client IDs, error codes, trace IDs, and correlation IDs.

CWE CWE-200
Vendor cyberlord92
Product powerbi embed reports
Published Oct 18, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for cyberlord92 powerbi embed reports

Be the first to know when new medium vulnerabilities affecting cyberlord92 powerbi embed reports are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

cyberlord92 / PowerBI Embed Reports
0 โ‰ค 1.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/d830c2eb-16e8-425c-ac46-a467a2fd0133?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/embed-power-bi-reports/tags/1.2.0/embed-microsoft-power-bi-reports.php#L75 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/embed-power-bi-reports/tags/1.2.0/Observer/adminObserver.php#L54 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/embed-power-bi-reports/tags/1.2.0/Observer/adminObserver.php#L265 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3369956%40embed-power-bi-reports&new=3369956%40embed-power-bi-reports&sfp_email=&sfph_mail=

Credits

Jonas Benjamin Friedli