CVE-2026-3235

WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps <= 5.5.68 - Unauthenticated Insecure Direct Object Reference to Data Access

The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app containers by exploiting a mismatch between the authorization check (performed against app_id) and data retrieval (performed using cnt_id without verifying container ownership).


We have discovered 1,990 live websites that are affected by CVE-2026-3235.

Run a Free Instant Scan




Affected Software

Product  Wp Data Access
Category Wordpress Plugins
Vulnerable Domains1,990 live websites (50% of Wp Data Access install base)
Vulnerable Versions
  • from 0 through 5.5.68
Vulnerable Versions Count73 versions ( 87% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Aug 26, 2026
  • Updated - Aug 26, 2026

Credits

  • type5afe (finder)

Website Distribution by Country

Number of websites using CVE-2026-3235
United States700 websites



Germany192 websites
France96 websites
Italy87 websites
GB83 websites
Spain55 websites
Netherlands53 websites
Poland53 websites
Canada46 websites
Brazil34 websites

Website Distribution by TLD

Number of websites using CVE-2026-3235
.com805 websites
.org168 websites
.de104 websites
.it61 websites
.co.uk49 websites
.nl43 websites
.net42 websites
.pl38 websites
.fr36 websites
.ca30 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-3235

Top websites that are affected by CVE-2026-3235. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com Canada*,***
*******.com United States**,***
*****.com United States**,***
***.org GB**,***
*********.***.ua Ukraine**,***
****.org United States**,***
******************.org Belize**,***
********.com United States***,***
************.com United States***,***
***********.com United States***,***
See full domain list

FAQ

CVE-2026-3235 is Authorization Bypass Through User-Controlled Key in Wp Data Access
A total of 1,990 websites have been identified as vulnerable to CVE-2026-3235, based on global website indexing conducted by WebTechSurvey.
The Wp Data Access is affected by the CVE-2026-3235 vulnerability.
Wp Data Access versions up to and including 5.5.68 are vulnerable to CVE-2026-3235.