Wpdataaccess Wp Data Access vulnerabilities
3 known vulnerabilities affecting wpdataaccess/wp_data_access.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-1874P2HIGHCVSS 8.8≤ 5.3.72023-04-12
CVE-2023-1874 [HIGH] CWE-266 CVE-2023-1874: The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple_roles_update function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wpda_rol
nvd
CVE-2021-24866P3CRITICALCVSS 9.8fixed in 5.0.02021-12-06
CVE-2021-24866 [CRITICAL] CWE-89 CVE-2021-24866: The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_da
The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion
nvd
CVE-2024-43295P4MEDIUMCVSS 4.3fixed in 5.5.92024-08-26
CVE-2024-43295 [MEDIUM] CWE-352 CVE-2024-43295: Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This i
Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V. WP Data Access.This issue affects WP Data Access: from n/a through 5.5.7.
nvd