Medium severity5.3NVD Advisory· Published Aug 26, 2026· Updated Aug 26, 2026
CVE-2026-3235
CVE-2026-3235
Description
The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app containers by exploiting a mismatch between the authorization check (performed against app_id) and data retrieval (performed using cnt_id without verifying container ownership).
Affected products
2<=5.5.68+ 1 more
- (no CPE)range: <=5.5.68
- (no CPE)range: <=5.5.68
Patches
Vulnerability mechanics
References
5- plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/API/WPDA_Apps.phpnvd
- plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/API/WPDA_Apps.phpnvd
- plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/Plugin_Table_Models/WPDA_App_Container_Model.phpnvd
- plugins.trac.wordpress.org/changeset/3477673/nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/935f5d76-d63a-4db4-b645-b7961ae8bfafnvd
News mentions
0No linked articles in our index yet.