Vulnerability Description
The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-party API requests using the site's own configured API key, and to create an unbounded number of attacker-controlled rows in the database.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-84936?
CVE-2026-84936 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make repeated billable third-par...
How severe is CVE-2026-84936?
CVE-2026-84936 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-84936?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.