Impact
The Dataverse Integration (DataPress) WordPress plugin fails to restrict access to its template rendering feature, allowing users with Contributor or higher roles to supply arbitrary template data. This vulnerability enables server‑side template injection (SSTI), letting the attacker view the session cookies of privileged users who view the affected content, potentially facilitating account hijacking or further exploitation.
Affected Systems
DataPress (Dataverse Integration) WordPress plugin versions prior to 2.91 are affected. Any instance of the plugin deploying those versions should be examined.
Risk and Exploitability
The CVSS score of 6.8 indicates medium severity. EPSS of < 1% (approximately 0.4%) indicates a low yet non‑zero risk of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation at present. The attack likely requires the user to possess at least Contributor privileges and to trigger the template rendering mechanism, which can be performed through normal site interactions such as editing or viewing content that invokes the vulnerable component.
OpenCVE Enrichment