Executive brief
WP Data Access is a WordPress plugin that enables data management and database access from the WordPress admin interface. This vulnerability allows unauthenticated attackers to bypass access controls and view or manipulate data they should not be permitted to access, potentially exposing sensitive customer or business information stored in the WordPress database.
Technical details
The vulnerability is a broken access control flaw in WP Data Access versions 5.5.80 and earlier that permits unauthenticated users to access restricted pages and perform unauthorized actions. The vulnerability does not require authentication, making it exploitable from the network without valid credentials. Attackers can view other users' data or perform privileged actions on the affected WordPress installation. A patch is available in version 5.5.81 and later.
Affected products
- WP Data Access WP Data Access <=5.5.80
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Patch available in version 5.5.81