๐Ÿ” CVE Alert

CVE-2026-84926

LOW 2.7

EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST Route

CVSS Score
2.7
EPSS Score
0.0%
EPSS Percentile
0th

The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.

Vendor unknown
Product embedpress
Published Sep 5, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown embedpress

Be the first to know when new low vulnerabilities affecting unknown embedpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / EmbedPress
4.6.0 < 4.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5f1bc0f2-1112-4f75-b2b6-27498e43cd4b/

Credits

Revanth Hari Narayana Matte WPScan