๐Ÿ” CVE Alert

CVE-2026-84927

LOW 2.7

EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification

CVSS Score
2.7
EPSS Score
0.0%
EPSS Percentile
0th

The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.

Vendor unknown
Product embedpress
Published Sep 5, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown embedpress

Be the first to know when new low vulnerabilities affecting unknown embedpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / EmbedPress
4.6.0 < 4.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/12984501-5d93-4941-9e12-6bb8049bd23d/

Credits

Artus KG WPScan