Sensitive Information Exposure in PowerBI Embed Reports Plugin for WordPress
CVE-2025-10750

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 October 2025

What is CVE-2025-10750?

The PowerBI Embed Reports plugin for WordPress has a vulnerability that permits unauthenticated attackers to access sensitive Azure Active Directory (AD) user information. This includes personal identifiable information (PII) like display names, email addresses, phone numbers, and department details. The issue stems from a lack of capability checks and authentication verification on the 'testUser' endpoint in the mo_epbr_admin_observer() function during the 'init' event. Attackers can exploit this flaw to retrieve detailed OAuth error data, including Azure AD Application/Client IDs, error codes, trace IDs, and correlation IDs, thereby compromising user privacy and data security.

Affected Version(s)

PowerBI Embed Reports * <= 1.2.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-10750 : Sensitive Information Exposure in PowerBI Embed Reports Plugin for WordPress