CVE-2026-84936 PUBLISHED

EmbedPress 4.6.0 - 4.6.3 - Unauthenticated Google Reviews API Quota Consumption and Database Bloat

Assigner: WPScan
Reserved: 02.09.2026 Published: 05.09.2026 Updated: 05.09.2026

The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database.

Product Status

Vendor Unknown
Product EmbedPress
Versions Default: unaffected
  • affected from 4.6.0 to 4.6.4 (excl.)

Credits

  • RIA Labs finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE