CVE-2026-84927
N/A
N/A
Summary
The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | EmbedPress | 4.6.0 < 4.6.4 | affected |
Weaknesses
- CWE-862 Missing Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.