SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-84927

LOW · CVSS 2.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The EmbedPress WordPress plugin prior to version 4.6.4 is vulnerable due to inadequate authorization checks on its Google Reviews REST API, enabling users with Contributor roles and higher to alter site-wide store configurations. This flaw allows unauthorized modifications, including the deletion of administrator-configured entries and the injection of malicious content, which can be publicly displayed on the site. WordPress site administrators and security teams should prioritize this vulnerability to prevent potential misuse and maintain the integrity of their sites.

CVE
CVE-2026-84927
Severity
LOW
CVSS
2.7
EPSS
0.17%
WordPress

Original NVD Description

The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.