CVE-2026-84926 PUBLISHED

EmbedPress 4.6.0 - 4.6.3 - Contributor+ Administrator Email Disclosure via Google Reviews REST Route

Assigner: WPScan
Reserved: 02.09.2026 Published: 05.09.2026 Updated: 05.09.2026

The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.

Product Status

Vendor Unknown
Product EmbedPress
Versions Default: unaffected
  • affected from 4.6.0 to 4.6.4 (excl.)

Credits

  • Revanth Hari Narayana Matte finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE