Executive brief
WP Data Access is a WordPress plugin that allows administrators to manage and query website databases through the WordPress interface. An unauthenticated attacker can exploit a SQL injection vulnerability to read, modify, or delete the entire database, including user accounts and sensitive customer data, without needing valid login credentials.
Technical details
The vulnerability is a SQL injection flaw in WP Data Access versions 5.5.81 and earlier that requires no authentication. An attacker can inject arbitrary SQL commands through an unprotected input vector to execute database queries with full database permissions. This allows complete data exfiltration, data manipulation, or database destruction. The vulnerability has been patched in version 5.5.82 and later; immediate update is strongly recommended given the critical severity and ease of exploitation.
Affected products
- WP Data Access WP Data Access ≤ 5.5.81
Timeline
- 2026-08-31: disclosed
- 2026-08-28: patched: patched in version 5.5.82