CVE-2026-5336

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users who view the affected content.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-06 22:18

Updated : 2026-08-26 16:31


NVD link : CVE-2026-5336

Mitre link : CVE-2026-5336

CVE.ORG link : CVE-2026-5336


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine