CVE-2026-3235
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: security@wordfence.com (Secondary)
Description
The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app containers by exploiting a mismatch between the authorization check (performed against app_id) and data retrieval (performed using cnt_id without verifying container ownership).
References (5)
https://plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/API/WPDA_Apps.php#L2387
Source: security@wordfence.com
https://plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/API/WPDA_Apps.php#L2400
Source: security@wordfence.com
Source: security@wordfence.com
Source: security@wordfence.com
Source: security@wordfence.com
Timeline
No history available yet.