PatchSiren

EmbedPress CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW EmbedPress CVE published 2026-09-05

CVE-2026-84926

The EmbedPress WordPress plugin before version 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators. This allows any authenticated user with contributor-level access or above to read the site administrator's email address, a value typically withheld from non-administrative roles in WordPress core. The vulnerability highlights the importance of proper access c [truncated]