Executive brief
EmbedPress is a WordPress plugin used to embed videos, maps, and other social media content into websites. A security flaw allows unauthenticated visitors to access sensitive information that should be restricted to site administrators. This exposure could lead to further attacks or the leakage of private configuration data, potentially compromising the entire website.
Technical details
EmbedPress versions 4.5.2 and earlier are vulnerable to sensitive data exposure due to an authorization bypass through a user-controlled key (CWE-639). The vulnerability allows a remote, unauthenticated attacker to access sensitive information by manipulating input parameters. This occurs because the plugin fails to properly validate the authorization of the requester before returning data. An attacker can exploit this over the network without any user interaction to gain access to restricted information. The issue is resolved in version 4.5.3.
Affected products
- WPDeveloper EmbedPress <= 4.5.2
Timeline
- 2026-05-07: other: Reported by Mukhlis Amien
- 2026-06-01: patched: Version 4.5.3 released
- 2026-06-15: disclosed: NVD publication date