The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contributor role and above to modify a site-wide store, deleting entries an administrator configured and injecting their own, which are rendered publicly across the site.
CVE-2026-84927
NONE
EPSS 0.13%
Updated Sep 05, 2026
Google
CVE Details
CVE ID
CVE-2026-84927
Published Date
Sep 05, 2026
Vendor
Google
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.13%
Likelihood of exploitation in next 30 days
Percentile:
3.1th percentile (higher than 3.1% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory