---
id: CVE-2025-10750
title: >-
  The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive
  Information Disclosure in all versions up to, and including, 1.2.0
summary: >-
  The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive
  Information Disclosure in all versions up to, and including, 1.2.0. This is
  due to missing capability checks and authentication verification on the
  'testUser' endp…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
published: '2025-10-18'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10750'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/embed-power-bi-reports/tags/1.2.0/Observer/adminObserver.php#L265
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/embed-power-bi-reports/tags/1.2.0/Observer/adminObserver.php#L54
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/embed-power-bi-reports/tags/1.2.0/embed-microsoft-power-bi-reports.php#L75
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3369956%40embed-power-bi-reports&new=3369956%40embed-power-bi-reports&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/d830c2eb-16e8-425c-ac46-a467a2fd0133?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00471
epssPercentile: 0.38789
ingestedAt: '2026-10-08T22:11:53.810Z'
---

## Overview

The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.2.0. This is due to missing capability checks and authentication verification on the 'testUser' endpoint accessible via the mo_epbr_admin_observer() function hooked on 'init'. This makes it possible for unauthenticated attackers to access sensitive Azure AD user information including personal identifiable information (PII) such as displayName, mail, phones, department, or detailed OAuth error data including Azure AD Application/Client IDs, error codes, trace IDs, and correlation IDs.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
