SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84936

MEDIUM · CVSS 5.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-05 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The EmbedPress plugin for WordPress prior to version 4.6.4 is vulnerable due to inadequate authorization on a public review-loading action, enabling unauthenticated users to exploit the site. This flaw allows attackers to generate unlimited billable third-party API requests using the site's API key and to create numerous unauthorized entries in the database. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential financial and data integrity risks.

CVE
CVE-2026-84936
Severity
MEDIUM
CVSS
5.3
EPSS
0.18%
WordPress

Original NVD Description

The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database.