Dataverse Integration WordPress Plugin Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability has been identified in the Dataverse Integration plugin for WordPress, specifically in versions 2.77 to 2.81. The issue arises from inadequate authorization checks in the reset_password_link REST endpoint. This endpoint allows authenticated users with Subscriber-level access and above to request password reset links for administrators, potentially leading to account hijacking.

Impact

Exploitation of this vulnerability allows authenticated users with Subscriber-level access and above to obtain password reset links for administrators, facilitating account hijacking.

Remediation

Users are advised to update the Dataverse Integration plugin to version 2.81.1 or a newer patched version.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.9
remediation
7.7
relevance
0.3
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.