WPDataAccess is a WordPress plugin providing database connectivity and front-end access controls, with its observed vulnerability surface centered on web-application input handling and privilege management. The recurring weakness classes—cross-site request forgery, SQL injection, and incorrect privilege assignment—reflect the authentication and data-access demands of a plugin bridging user input to backend database operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpdataaccess over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1874HIGH The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple | Apr 12, 2023 | 8.8 | 30 | NO | NO |
CVE-2021-24866CRITICAL The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue a | Dec 6, 2021 | 9.8 | 30 | NO | NO |
CVE-2024-43295MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This issue affects WP Data Access: from n/a through 5.5.7. | Aug 26, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdataaccess.
Media articles that mention a CVE ID that affects a product developed by Wpdataaccess — matched by CVE ID, not by vendor name.