Sensitive Information Exposure in PowerBI Embed Reports Plugin for WordPress
CVE-2025-10750
What is CVE-2025-10750?
The PowerBI Embed Reports plugin for WordPress has a vulnerability that permits unauthenticated attackers to access sensitive Azure Active Directory (AD) user information. This includes personal identifiable information (PII) like display names, email addresses, phone numbers, and department details. The issue stems from a lack of capability checks and authentication verification on the 'testUser' endpoint in the mo_epbr_admin_observer() function during the 'init' event. Attackers can exploit this flaw to retrieve detailed OAuth error data, including Azure AD Application/Client IDs, error codes, trace IDs, and correlation IDs, thereby compromising user privacy and data security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PowerBI Embed Reports * <= 1.2.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved