Impact
The WP Data Access plugin contains an unauthenticated broken access control flaw that allows any user to view protected data. This vulnerability is specifically classified as CWE-862, which highlights that access permissions are not correctly enforced. An attacker who can reach the vulnerable plugin endpoints can retrieve or modify data that should otherwise be restricted, resulting in potential confidentiality and integrity breaches.
Affected Systems
The flaw affects the WP Data Access plugin by Passionate Programmer Peter, for all releases up to and including version 5.5.80. No newer versions are listed as impacted, and no additional version ranges are specified in the current advisory.
Risk and Exploitability
The CVSS score of 5.9izes the issue as medium severity. Because the attack vector requires unauthenticated web access, the exploitation effort is low; however, no EPSS score is provided and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not yet been observed. The primary risk is that an attacker could gain unauthorized access to database content through the plugin's exposed endpoints.
OpenCVE Enrichment