WordPress Plugin Vulnerabilities

WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass

Description

The plugin does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to, including user password hashes where that table is the users table.

Proof of Concept

Affects Plugins

Fixed in 5.5.79

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE
CVSS

Miscellaneous

Original Researcher
Farid Narimanov
Submitter
Farid Narimanov
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 27 days ago)
Added
2026-08-03 (about 26 days ago)
Last Updated
2026-08-06 (about 24 days ago)

Other