Sensitive Information Exposure in PowerBI Embed Reports Plugin for WordPress
CVE-2025-10750
5.3MEDIUM
What is CVE-2025-10750?
The PowerBI Embed Reports plugin for WordPress has a vulnerability that permits unauthenticated attackers to access sensitive Azure Active Directory (AD) user information. This includes personal identifiable information (PII) like display names, email addresses, phone numbers, and department details. The issue stems from a lack of capability checks and authentication verification on the 'testUser' endpoint in the mo_epbr_admin_observer() function during the 'init' event. Attackers can exploit this flaw to retrieve detailed OAuth error data, including Azure AD Application/Client IDs, error codes, trace IDs, and correlation IDs, thereby compromising user privacy and data security.
Affected Version(s)
PowerBI Embed Reports * <= 1.2.0