CVE-2026-66595: WordPress WP Data Access plugin <= 5.5.80 - Broken Access Control vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
Affected Software
1 affected component
WP Data Access<=5.5.80
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Data Access pluginto a version that resolves this vulnerability.Fixed in 5.5.81
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need a WordPress account or user interaction to exploit this issue?
No. The CVSS vector indicates no privileges are required and no user interaction is required; the attack can be conducted over the network.
2
What impact is indicated if the vulnerability is exploited?
The CVSS vector indicates high confidentiality impact, with no indicated integrity or availability impact. Exploitation is rated as high complexity.