Unauthenticated Broken Access Control in WP Data Access by WordPress
CVE-2026-66595
5.9MEDIUM
What is CVE-2026-66595?
The vulnerability identified in WP Data Access versions up to 5.5.80 allows unauthenticated users to exploit insufficient access controls. This flaw could enable attackers to access restricted areas of the application, potentially leading to data exposure or unauthorized actions. It is crucial for users of this plugin to implement updates and mitigate risks by reviewing their security settings.
Affected Version(s)
WP Data Access <= 5.5.80