The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app containers by exploiting a mismatch between the authorization check (performed against app_id) and data retrieval (performed using cnt_id without verifying container ownership).
We have discovered 1,990 live websites that are affected by CVE-2026-3235.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,990 live websites (50% of Wp Data Access install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 73 versions ( 87% of all versions) |
| 700 websites | |
| 192 websites | |
| 96 websites | |
| 87 websites | |
| 83 websites | |
| 55 websites | |
| 53 websites | |
| 53 websites | |
| 46 websites | |
| 34 websites |
| .com | 805 websites |
| .org | 168 websites |
| .de | 104 websites |
| .it | 61 websites |
| .co.uk | 49 websites |
| .nl | 43 websites |
| .net | 42 websites |
| .pl | 38 websites |
| .fr | 36 websites |
| .ca | 30 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *************.com | *,*** | ||
| *******.com | **,*** | ||
| *****.com | **,*** | ||
| ***.org | **,*** | ||
| *********.***.ua | **,*** | ||
| ****.org | **,*** | ||
| ******************.org | **,*** | ||
| ********.com | ***,*** | ||
| ************.com | ***,*** | ||
| ***********.com | ***,*** |
FAQ