CyberRota Analysis
AI-GeneratedThe EmbedPress WordPress plugin prior to version 4.6.4 has a vulnerability that allows authenticated users with contributor-level access or higher to access sensitive Google Reviews REST routes, exposing the site administrator's email address. This unauthorized access undermines user privacy and could lead to further exploitation of the site. WordPress site administrators and security teams should prioritize updating this plugin to mitigate potential risks.
Original NVD Description
The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.