CVE-2026-84936
Received Received - Intake

Unauthenticated API Abuse in EmbedPress Plugin

Vulnerability report for CVE-2026-84936, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: WPScan

Description

The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
embedpress embedpress to 4.6.4 (exc)
ria_labs embedpress to 4.6.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The EmbedPress WordPress plugin before version 4.6.4 has a vulnerability where an unauthenticated user can trigger a public action that forces the site to make repeated billable API requests to third-party services like Google Reviews using the site's own API key. This can lead to excessive API usage and financial costs. Additionally, attackers can create an unlimited number of database entries, causing database bloat.

Detection Guidance

Check if your EmbedPress plugin version is between 4.6.0 and 4.6.3. Look for unusual API request logs or spikes in third-party API usage, especially to Google Reviews. Monitor database growth for unexpected row additions.

Impact Analysis

This vulnerability can impact you by increasing your API usage costs due to repeated billable requests made using your API key. It can also cause your website's database to grow excessively, leading to performance issues or crashes. Unauthorized database entries may also disrupt normal site operations.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA due to unauthorized API requests and database modifications. Uncontrolled API usage may lead to excessive data processing, which could violate GDPR principles of data minimization and purpose limitation. Additionally, unauthorized database entries might expose or mishandle sensitive personal data, risking GDPR compliance. For HIPAA, if the site handles protected health information, unauthorized API calls or database changes could compromise data integrity or confidentiality.

Mitigation Strategies

Update the EmbedPress plugin to version 4.6.4 or later immediately. Disable the public review-loading action if not needed. Review API keys for third-party services and revoke any exposed keys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-84936. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart