Medium severity5.3NVD Advisory· Published Aug 26, 2026· Updated Aug 28, 2026
CVE-2026-3235
CVE-2026-3235
Description
The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app containers by exploiting a mismatch between the authorization check (performed against app_id) and data retrieval (performed using cnt_id without verifying container ownership).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=5.5.68+ 1 more
- (no CPE)range: <=5.5.68
- (no CPE)range: <=5.5.68
Patches
Vulnerability mechanics
References
5- plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/API/WPDA_Apps.phpnvd
- plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/API/WPDA_Apps.phpnvd
- plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/Plugin_Table_Models/WPDA_App_Container_Model.phpnvd
- plugins.trac.wordpress.org/changeset/3477673/nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/935f5d76-d63a-4db4-b645-b7961ae8bfafnvd
News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 24, 2026 to August 30, 2026)Wordfence Blog · Sep 3, 2026
- WordPress: 25 Plugins and Themes Hit by Vulnerabilities, Including Critical RCE and File Upload FlawsVypr Intelligence · Aug 26, 2026