PT-2025-30655 · WordPress · Dataverse Integration

Kenneth Dunn

·

Published

2025-07-24

·

Updated

2025-07-29

·

CVE-2025-7695

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dataverse Integration versions 2.77 through 2.81
Description The plugin is susceptible to privilege escalation due to missing authorization checks within the reset password link REST endpoint. The endpoint’s handler unconditionally calls get password reset key() after verifying only that the caller is authenticated, allowing any authenticated attacker with Subscriber-level access or higher to obtain a password reset link for an administrator and potentially hijack the account. The vulnerable endpoint is /reset password link. The vulnerable parameters include id, email, and login.
Recommendations Dataverse Integration versions 2.77 through 2.81: Update to a version beyond 2.81, if available. As a temporary workaround, restrict access to the reset password link endpoint to authorized personnel only.

Fix

LPE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-7695

Affected Products

Dataverse Integration