Vulnerability in WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards — CVE-2026-3235
MediumSeverity
0.2%Estimated exploit probability
10,000+ sitesInstalls
5.5.69Fixed in
What to do now
Update WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards to 5.5.69 or later.
Affected versions
- Everything up to and including 5.5.68
Affected: WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards (plugin, wp-data-access)
What the vulnerability is
The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app containers by exploiting a mismatch between the authorization check (performed against app_id) and data retrieval (performed using cnt_id without verifying container ownership).
Sources
- https://plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/API/WPDA_Apps.php#L2387
- https://plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/API/WPDA_Apps.php#L2400
- https://plugins.trac.wordpress.org/browser/wp-data-access/trunk/WPDataAccess/Plugin_Table_Models/WPDA_App_Container_Model.php#L50
- https://plugins.trac.wordpress.org/changeset/3477673/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/935f5d76-d63a-4db4-b645-b7961ae8bfaf?source=cve