SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-84926

LOW · CVSS 2.7 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The EmbedPress WordPress plugin prior to version 4.6.4 has a vulnerability that allows authenticated users with contributor-level access or higher to access sensitive Google Reviews REST routes, exposing the site administrator's email address. This unauthorized access undermines user privacy and could lead to further exploitation of the site. WordPress site administrators and security teams should prioritize updating this plugin to mitigate potential risks.

CVE
CVE-2026-84926
Severity
LOW
CVSS
2.7
EPSS
0.19%
WordPress

Original NVD Description

The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.