Dataverse Integration WordPress Plugin Privilege Escalation Vulnerability
Vulnerability
A privilege escalation vulnerability has been identified in the Dataverse Integration plugin for WordPress, specifically in versions 2.77 to 2.81. The issue arises from inadequate authorization checks in the reset_password_link REST endpoint. This endpoint allows authenticated users with Subscriber-level access and above to request password reset links for administrators, potentially leading to account hijacking.
Impact
Exploitation of this vulnerability allows authenticated users with Subscriber-level access and above to obtain password reset links for administrators, facilitating account hijacking.
Remediation
Users are advised to update the Dataverse Integration plugin to version 2.81.1 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
