The db-access WordPress plugin through 0.8.7 does not...
High severity
Unreviewed
Published
Dec 2, 2025
to the GitHub Advisory Database
•
Updated Jan 30, 2026
Description
Published by the National Vulnerability Database
Dec 2, 2025
Published to the GitHub Advisory Database
Dec 2, 2025
Last updated
Jan 30, 2026
The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacks
References