Junglewise Threat Intelligence

CVE-2026-42665: WP Data Access unauthenticated SQL injection

CVE-2026-42665 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Executive brief

WP Data Access, a WordPress plugin used for managing and displaying database tables, contains a critical security flaw. An unauthenticated attacker can remotely access and manipulate the website's database without needing a password. This could lead to the theft of sensitive customer information, unauthorized modification of site content, or a partial disruption of services.

Technical details

A SQL injection vulnerability (CWE-89) exists in the WP Data Access plugin for WordPress due to improper neutralization of special elements in SQL commands. The flaw is accessible to unauthenticated remote attackers over the network with low attack complexity. By sending specially crafted requests, an attacker can bypass security controls to directly interact with the underlying database. This can result in high-impact data exfiltration and limited impact on system availability. The vulnerability is patched in version 5.5.71.

Affected products

  • WP Data Access WP Data Access <= 5.5.70

Timeline

  • 2026-04-09: other: Reported by Mukhlis Amien
  • 2026-05-09: advisory: Initial advisory published by Patchstack
  • 2026-06-15: disclosed: CVE published to NVD
  • 2026-05-09: patched: Version 5.5.71 released to address the vulnerability

References

Related threats