CVE-2026-84926
The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user with contributor-level access or above to read the site administrator's email address, a value WordPress core withholds from that role.
- Published Sep 5, 2026
- CVSS 2.7 low
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available