---
id: CVE-2026-95605
title: >-
  Improper Neutralization of Special Elements used in an SQL Command ('SQL
  Injection') vulnerability in Passionate Programmer Peter WP Data Access allows
  Blind SQL Injection.


  This issue affects WP Data Access: from n/a through 5.5.82.
summary: >-
  Improper Neutralization of Special Elements used in an SQL Command ('SQL
  Injection') vulnerability in Passionate Programmer Peter WP Data Access allows
  Blind SQL Injection.


  This issue affects WP Data Access: from n/a through 5.5.82.
severity: critical
cvss: 9.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'
cwe:
  - CWE-89
vendor: Passionate Programmer Peter
product: wp-data-access
affected:
  - wp-data-access >= n/a <= 5.5.82
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:17:04.063'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95605'
references:
  - url: >-
      https://patchstack.com/database/wordpress/plugin/wp-data-access/vulnerability/wordpress-wp-data-access-plugin-5-5-82-sql-injection-vulnerability?_s_id=cve
    label: audit@patchstack.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T17:40:37.546Z'
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-07T18:02:40.345076Z'
---

## Overview

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Passionate Programmer Peter WP Data Access allows Blind SQL Injection.

This issue affects WP Data Access: from n/a through 5.5.82.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
