PatchSiren

WP Data Access CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review WP Data Access CVE published 2026-08-09

CVE-2026-18032

The WP Data Access WordPress plugin before 5.5.79 does not validate column names on an unauthenticated AJAX action, potentially allowing arbitrary database column reads, including user password hashes. This vulnerability affects WP Data Access plugin users, WordPress administrators, security teams, and operators of affected systems. The CVE record was published on 2026-08-09T06:18:22.640Z and has not been [truncated]