Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection.

This issue affects WP Data Access: from n/a through 5.5.82.
Published: 2026-10-07
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Data Compromise
Action: Immediate Patch
AI Analysis

Impact

The WP Data Access plugin for WordPress, versions up through 5.5.82, contains a flaw that permits blind SQL injection because user input is not properly sanitized. This weakness, classified as CWE‑89, allows an attacker who can send crafted requests to the plugin to execute arbitrary SQL statements, enabling unauthorized reading, modification, or deletion of database contents. Such activity threatens the confidentiality and integrity of site data.

Affected Systems

All installations of the WordPress WP Data Access plugin from any version down through 5.5.82 are impacted. The plugin is distributed by Passionate Programmer Peter. Any version beyond 5.5.82, including the patched 5.5.83 release, contains the fix.

Risk and Exploitability

The CVSS score of 9.3 indicates a high‑severity vulnerability. No EPSS score is available, so the exploitation probability is unknown, but the vulnerability is not listed in CISA’s KEV catalog, suggesting no documented exploitation in the wild so far. Based on the description, the likely attack vector is remote via the plugin’s HTTP interface, and no special privileges are needed beyond ordinary interaction with the plugin. Therefore, every site running an affected version faces a significant risk if the patch is not applied.

Generated by OpenCVE AI on October 7, 2026 at 18:57 UTC.

Remediation

Vendor Solution

Update the WordPress WP Data Access Plugin to the latest available version (at least 5.5.83).


OpenCVE Recommended Actions

  • Update the WP Data Access plugin to version 5.5.83 or later.
  • If an update cannot be performed immediately, disable or remove the plugin from the site until a secure version is available.
  • Inspect the database for unexpected tables or data alterations that may have resulted from exploitation.
  • Enable comprehensive logging of database queries and review logs for suspicious activity.

Generated by OpenCVE AI on October 7, 2026 at 18:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection. This issue affects WP Data Access: from n/a through 5.5.82.
Title WordPress WP Data Access plugin <= 5.5.82 - SQL Injection vulnerability
First Time appeared Passionate Programmer Peter
Passionate Programmer Peter wp Data Access
Weaknesses CWE-89
CPEs cpe:2.3:a:passionate_programmer_peter:wp_data_access:*:*:*:*:*:*:*:*
Vendors & Products Passionate Programmer Peter
Passionate Programmer Peter wp Data Access
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Passionate Programmer Peter Wp Data Access
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-07T18:04:51.175Z

Reserved: 2026-09-22T09:18:20.380Z

Link: CVE-2026-95605

cve-icon Vulnrichment

Updated: 2026-10-07T18:02:40.998Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:04.063

Modified: 2026-10-07T19:17:45.353

Link: CVE-2026-95605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T19:00:16Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')