CVE-2026-81293: WordPress WP Data Access plugin <= 5.5.81 - SQL Injection vulnerability
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Data Access pluginto a version that resolves this vulnerability.Fixed in 5.5.82
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or prior access to the site. The attack vector is network-based and requires low complexity with no user interaction.
Which installations are affected?
WP Data Access versions 5.5.81 and earlier are identified as affected. The provided information does not state whether any particular plugin configuration or feature must be enabled.
What could exploitation allow?
The vulnerability is SQL injection with high confidentiality impact and low availability impact. The supplied data does not identify specific database data, affected endpoints, or confirmed exploitation outcomes.