Unauthenticated SQL Injection in WP Data Access by WordPress
CVE-2026-42665
9.3CRITICAL
What is CVE-2026-42665?
An SQL injection vulnerability exists in WP Data Access versions up to 5.5.70, allowing attackers to exploit the plugin without authentication. This can lead to unauthorized data manipulation and exposure of sensitive information. It is essential for users of this plugin to update to the latest version to mitigate the risk and protect their databases from potential compromise.
Affected Version(s)
WP Data Access <= 5.5.70