๐Ÿ” CVE Alert

CVE-2026-84936

MEDIUM 5.3

EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database Bloat

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database.

Vendor unknown
Product embedpress
Published Sep 5, 2026
Last Updated Sep 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown embedpress

Be the first to know when new medium vulnerabilities affecting unknown embedpress are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / EmbedPress
4.6.0 < 4.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/bd708c98-1657-423b-aa2b-14aa18307c03/

Credits

RIA Labs WPScan