Impact
WordPress WP Data Access plugin versions up to 5.5.79 contain an unsanitized input handler that can be exploited for Cross Site Scripting. An attacker can inject arbitrary JavaScript that executes in the browser of any user who views data generated by this plugin, potentially leading to session hijacking, defacement, or malicious redirects.
Affected Systems
All installations of the WP Data Access plugin from Passionate Programmer Peter, specifically versions 5.5.79 and earlier, are affected. Updates to 5.5.80 or newer remove the vulnerability.
Risk and Exploitability
With a CVSS score of 5.9, the vulnerability is considered medium severity. No EPSS score is available, and it is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request that contains malicious payloads rendered by the plugin. An attacker would need to supply a crafted input that the plugin processes without proper sanitization; this could be delivered through a user‑facing form or data entry. While no active exploits are documented, the nature of XSS means attackers could attempt to trick users into opening malicious links or modifying plugin‑generated content to execute arbitrary JavaScript in the victim’s browser.
OpenCVE Enrichment