CyberRota Analysis
AI-GeneratedThe EmbedPress WordPress plugin prior to version 4.6.4 is vulnerable due to inadequate authorization checks on its Google Reviews REST API, enabling users with Contributor roles and higher to alter site-wide store configurations. This flaw allows unauthorized modifications, including the deletion of administrator-configured entries and the injection of malicious content, which can be publicly displayed on the site. WordPress site administrators and security teams should prioritize this vulnerability to prevent potential misuse and maintain the integrity of their sites.
Original NVD Description
The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.