What the vulnerability does
01Description
The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users who view the affected content.
Explanation of Vulnerability in Simple Terms
02Summary
DataPress versions before 2.91 contain a vulnerability that allows authenticated administrators with high privileges to perform actions with significant impact when user interaction is involved. An attacker with admin-level access can read sensitive data, modify site content, or disrupt service availability. The vulnerability requires the attacker to have administrative credentials and the victim to interact with a malicious link or page.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify content, or disrupt service availability if they have admin access.
Potential impact on your site
04Site Impact
If an admin account is compromised, an attacker can access confidential data, alter site content, or cause downtime.
Conditions required to exploit
05Prerequisites
Attacker must have high-level administrative privileges and the victim must click a link or visit a page.
Key dates
06Disclosure timeline
August 6, 2026
CVE published