Junglewise Threat Intelligence

CVE-2026-81293: WP Data Access SQL Injection

CVE-2026-81293 · Severity: critical · CVSS 9.3 · Published 2026-08-31

Executive brief

WP Data Access is a WordPress plugin that allows administrators to manage and query website databases through the WordPress interface. An unauthenticated attacker can exploit a SQL injection vulnerability to read, modify, or delete the entire database, including user accounts and sensitive customer data, without needing valid login credentials.

Technical details

The vulnerability is a SQL injection flaw in WP Data Access versions 5.5.81 and earlier that requires no authentication. An attacker can inject arbitrary SQL commands through an unprotected input vector to execute database queries with full database permissions. This allows complete data exfiltration, data manipulation, or database destruction. The vulnerability has been patched in version 5.5.82 and later; immediate update is strongly recommended given the critical severity and ease of exploitation.

Affected products

  • WP Data Access WP Data Access ≤ 5.5.81

Timeline

  • 2026-08-31: disclosed
  • 2026-08-28: patched: patched in version 5.5.82

References

Related threats