← Back to overview

A critical unauthenticated SQL injection vulnerability has been identified in the WP Data Access WordPress plugin affecting versions 5.5.81 and below. The vulnerability allows unauthenticated attackers to perform SQL injection attacks, potentially enabling unauthorized access to the database, data exfiltration, and manipulation of stored data. As the exploit requires no authentication, the attack surface is particularly broad, making it accessible to any remote attacker. The vulnerability is tracked as CVE-2026-81293 and has been published on the NVD and Patchstack databases. Users are advised to update the plugin to a patched version immediately to mitigate the risk. The high criticality rating reflects the unauthenticated nature of the exploit and the potential for significant data compromise.

Affected products

  • WP Data Access WordPress Plugin <= 5.5.81

Related CVE's

  • CVE-2026-81293

Categories

  • Database & Storage
  • Web Technologies