Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.5
CVE-2026-18032: WP Data Access < 5.5.79 - Unauthenticated Password Exposure
CVE-2026-18032 · published 26 days ago
Summary
The WP Data Access plugin for WordPress allows unauthorized access to sensitive user data, including passwords, when using a specific form. This is a serious issue because attackers can potentially gain access to user credentials. To protect your users, update the WP Data Access plugin to version 5.5.79 or later.
What to do
- Update unknown wp data access to version 5.5.79 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | wp data access | < 5.5.79 |
Original advisory text
WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass
The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to, including user password hashes where that table is the users table.
References
- https://wpscan.com/vulnerability/1b6c5935-c8e0-4b9b-9ba6-0f16a0e2cdae/ exploit vdb-entry technical-description
Severity
7.5
High
Exploitation
EPSS <1%
Type
CWE-200Information Exposure
Timeline
Published9 Aug 2026
Updated29 Aug 2026
First seen9 Aug 2026
Monitor software like this
Free during beta