Extension WordPress
Vulnérabilités WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards
Cette page rassemble les failles publiées pour WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards
9 fiches
WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards <= 5.5.70 – Unauthenticated SQL Injection
The WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.5.70 due to insufficient escaping on the user supplied parameter…
*-5.5.70
5.5.71
09/05/2026
Freemius <= 2.10.1 – Reflected DOM-Based Cross-Site Scripting via url Parameter
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-5.5.31
5.5.32
30/04/2026
WP Data Access <= 5.5.63 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpda_app' Shortcode
The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpda_app' shortcode in all versions up to, and including, 5.5.63 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-5.5.63
5.5.64
13/02/2026
WP Data Access <= 5.5.36 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP Data Access plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.5.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
*-5.5.36
5.5.37
16/04/2025
WP Data Access – App, Table, Form and Chart Builder plugin <= 5.5.22 – Unauthenticated SQL Injection
The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via the 'order[user_login][dir]' parameter in all versions up to, and including, 5.5.22 due to insufficient escaping on the…
*-5.5.22
5.5.23
24/12/2024
WP Data Access <= 5.5.7 – Cross-Site Request Forgery
The WP Data Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.7. This is due to missing or incorrect nonce validation on the backup_page() function. This makes it possible for…
*-5.5.7
5.5.9
16/08/2024
WP Data Access <= 5.3.7 – Authenticated (Subscriber+) Privilege Escalation
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple_roles_update function. This makes it possible for authenticated…
*-5.3.7
5.3.8
06/04/2023
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 5.1.4)
5.1.4
04/03/2022
WP Data Access <= 4.3.1 – Admin+ SQL Injection
The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before using it a SQL statement, leading to a SQL injection issue and could allow arbitrary table deletion
*-4.3.1
5.0.0
08/11/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.