← Back

CVE-2026-84926

nvd nist
Published: Sep 5, 2026Modified: Sep 5, 2026

JSON object

Loading...

Description

The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.

Timeline

No history available yet.