The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users who view the affected content.
https://wpscan.com/vulnerability/3b3ab347-a8bd-4baa-8eba-c45a8a79e33f/