Impact
The WP Data Access plugin for WordPress, versions up through 5.5.82, contains a flaw that permits blind SQL injection because user input is not properly sanitized. This weakness, classified as CWE‑89, allows an attacker who can send crafted requests to the plugin to execute arbitrary SQL statements, enabling unauthorized reading, modification, or deletion of database contents. Such activity threatens the confidentiality and integrity of site data.
Affected Systems
All installations of the WordPress WP Data Access plugin from any version down through 5.5.82 are impacted. The plugin is distributed by Passionate Programmer Peter. Any version beyond 5.5.82, including the patched 5.5.83 release, contains the fix.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity vulnerability. No EPSS score is available, so the exploitation probability is unknown, but the vulnerability is not listed in CISA’s KEV catalog, suggesting no documented exploitation in the wild so far. Based on the description, the likely attack vector is remote via the plugin’s HTTP interface, and no special privileges are needed beyond ordinary interaction with the plugin. Therefore, every site running an affected version faces a significant risk if the patch is not applied.
OpenCVE Enrichment