Unauthenticated SQL Injection in WP Data Access Plugin by WordPress
CVE-2026-93621
8.2HIGH
What is CVE-2026-93621?
An unauthenticated SQL Injection vulnerability exists in the WP Data Access plugin for WordPress, affecting versions up to 5.5.84. This flaw allows attackers to exploit the application's database through specially crafted queries, which can lead to unauthorized data exposure and manipulation. Website owners are urged to update to the latest version to safeguard against potential exploitation and ensure the integrity of their data.
Affected Version(s)
WP Data Access <= 5.5.84