Loading market data...
← Back to CVE feed

CVE-2026-5336

MEDIUM CVSS 6.8 View on NVD ↗

Description

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users who view the affected content.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Published: Aug 06, 2026 22:18 UTC Modified: Aug 07, 2026 14:17 UTC