What is CVE-2026-18032?
The WP DataAccess plugin before version 5.5.79 fails to validate column names in an unauthenticated AJAX action, which lacks a proper nonce check, allowing unauthenticated attackers to read arbitrary columns from a database table. Immediate update to the latest version is recommended.
Azərbaycanca: WP DataAccess plaqini (5.5.79-dən əvvəlki versiyalar) autentifikasiya olunmamış AJAX sorğularında sütun adlarını düzgün yoxlamır, bu da autentifikasiyasız hücumçulara verilənlər bazası cədvəlinin ixtiyari sütunlarını oxumağa imkan verir. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What data can an attacker access by exploiting CVE-2026-18032?
An unauthenticated attacker can read arbitrary columns from a database table.
How can the CVE-2026-18032 vulnerability in WP DataAccess be mitigated?
It is recommended to immediately update the plugin to version 5.5.79 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.