CVE-2026-5336 MEDIUM

CVE-2026-5336: Dataverse Integration < 2.91 - Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure

Vendor Unknown
Product DataPress (Dataverse Integration)
Published August 6, 2026
Last update August 6, 2026

CVSS base score

6.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users who view the affected content.

Explanation of Vulnerability in Simple Terms

02Summary

DataPress versions before 2.91 contain a vulnerability that allows authenticated administrators with high privileges to perform actions with significant impact when user interaction is involved. An attacker with admin-level access can read sensitive data, modify site content, or disrupt service availability. The vulnerability requires the attacker to have administrative credentials and the victim to interact with a malicious link or page.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, or disrupt service availability if they have admin access.

Potential impact on your site

04Site Impact

If an admin account is compromised, an attacker can access confidential data, alter site content, or cause downtime.

Conditions required to exploit

05Prerequisites

Attacker must have high-level administrative privileges and the victim must click a link or visit a page.

Key dates

06Disclosure timeline

August 6, 2026 CVE published