SQL Injection Vulnerability in WP Data Access by Passionate Programmer Peter
CVE-2026-95605

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 October 2026

What is CVE-2026-95605?

An SQL Injection vulnerability in the WP Data Access plugin developed by Passionate Programmer Peter allows attackers to execute unauthorized SQL commands. This issue enables blind SQL injection, potentially leading to sensitive data exposure or manipulation. The vulnerability impacts all versions through 5.5.82, highlighting the need for immediate attention and prompt updates to safeguard data integrity and security within WordPress environments.

Affected Version(s)

WP Data Access <= 5.5.82

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

neurotx | Patchstack Bug Bounty Program
.