PT-2026-68753 · WordPress · Datapress
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DataPress (Dataverse Integration) WordPress plugin versions prior to 2.91
Description
Insufficient access restrictions in the template rendering feature allow users with Contributor roles to disclose sensitive information. This issue occurs because the feature exposes the data of the viewing user, which can be leveraged to obtain session cookies of higher privileged users who interact with the affected content.
Recommendations
Update the plugin to version 2.91 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Datapress