CVE-2026-84927 PUBLISHED

EmbedPress 4.6.0 - 4.6.3 - Contributor+ Google Reviews Modification

Assigner: WPScan
Reserved: 02.09.2026 Published: 05.09.2026 Updated: 05.09.2026

The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.

Product Status

Vendor Unknown
Product EmbedPress
Versions Default: unaffected
  • affected from 4.6.0 to 4.6.4 (excl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE