CVE-2026-81293
largeUnauthenticated SQL Injection in WP Data Access WordPress Plugin (<= 5.5.81)
CVE-2026-81293 is an unauthenticated SQL injection flaw (CWE-89) in the WP Data Access WordPress plugin, affecting all versions up to and including 5.5.81. Because the vulnerable code path is reachable over the network (AV:N) with low attack complexity and requires no privileges or user interaction, a remote, unauthenticated attacker can send crafted input to affected endpoints and have it processed as SQL. Successful exploitation could expose sensitive database content (high confidentiality impact) and, per the critical 9.3 CVSS score with changed scope (S:C), may affect components beyond the vulnerable code, while integrity and availability impacts are scored low. Any WordPress site running WP Data Access 5.5.81 or earlier is affected; sites without the plugin or on later versions are not. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and the 0.2% EPSS score (15th percentile) indicates a low estimated probability of exploitation in the next 30 days.
What to do: WordPress administrators should check whether any of their sites run WP Data Access 5.5.81 or earlier (Dashboard > Plugins) and update to the first available release newer than 5.5.81 as soon as a patched version is published, since the advisory does not name a fixed version. Until the update is applied, consider deactivating the plugin or restricting unauthenticated access to it, and review web server logs for unexpected requests or SQL errors indicating probing. No exploitation has been confirmed, so there is no evidence of compromise specific to this flaw, but routine log review is prudent.
| WP Data Access (WordPress plugin) | <= 5.5.81 (all versions up to and including 5.5.81) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.