Review
WP Data Access
CVE published 2026-08-09
CVE-2026-18032
The WP Data Access WordPress plugin before 5.5.79 does not validate column names on an unauthenticated AJAX action, potentially allowing arbitrary database column reads, including user password hashes. This vulnerability affects WP Data Access plugin users, WordPress administrators, security teams, and operators of affected systems. The CVE record was published on 2026-08-09T06:18:22.640Z and has not been [truncated]