CVE-2026-95605: WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection.
This issue affects WP Data Access: from n/a through 5.5.82.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Data Access Pluginto a version that resolves this vulnerability.Fixed in 5.5.83
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates it can be exploited remotely over the network without authentication or user interaction. Attackers do not need prior privileges.
What is the impact of successful exploitation?
The issue allows blind SQL injection. The supplied severity vector indicates high confidentiality impact and low availability impact, with no integrity impact listed.
Which versions are affected?
WP Data Access versions through 5.5.82 are affected. The available information does not identify a fixed version.