Vulnerabilities > Wpdataaccess

DATE CVE VULNERABILITY TITLE RISK
2024-08-26 CVE-2024-43295 Cross-Site Request Forgery (CSRF) vulnerability in Wpdataaccess WP Data Access
Cross-Site Request Forgery (CSRF) vulnerability in Passionate Programmers B.V.
network
low complexity
wpdataaccess CWE-352
4.3
2023-04-12 CVE-2023-1874 Unspecified vulnerability in Wpdataaccess WP Data Access
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7.
network
low complexity
wpdataaccess
8.8
2021-12-06 CVE-2021-24866 SQL Injection vulnerability in Wpdataaccess WP Data Access
The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion
network
low complexity
wpdataaccess CWE-89
critical
9.8