Unauthenticated SQL Injection in WP Data Access by WordPress
CVE-2026-42665

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-42665?

An SQL injection vulnerability exists in WP Data Access versions up to 5.5.70, allowing attackers to exploit the plugin without authentication. This can lead to unauthorized data manipulation and exposure of sensitive information. It is essential for users of this plugin to update to the latest version to mitigate the risk and protect their databases from potential compromise.

Affected Version(s)

WP Data Access <= 5.5.70

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mukhlis Amien | Patchstack Bug Bounty Program
.