CVE-2026-93621: WordPress WP Data Access plugin <= 5.5.84 - SQL Injection vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
Affected Software
1 affected component
wordpress/wp-data-access<=5.5.84
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Data Access pluginto a version that resolves this vulnerability.Fixed in 5.5.85
Event History
Sep 30, 2026
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation over the network.
2
Which installations are affected?
Installations using WP Data Access version 5.5.84 or earlier are affected according to the available information.
3
What is the likely security impact?
The vulnerability is rated high with an 8.2 CVSS score. Its vector indicates network-reachable exploitation with low attack complexity and no user interaction, with high confidentiality impact and low integrity impact.