CVE-2026-73344

WordPress WP Data Access plugin <= 5.5.79 - Cross Site Scripting (XSS) vulnerability

Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.


We have discovered 3,958 live websites that are affected by CVE-2026-73344.

Run a Free Instant Scan




Affected Software

Product  Wp Data Access
Category Wordpress Plugins
Vulnerable Domains3,958 live websites (100% of Wp Data Access install base)
Vulnerable Versions
  • from 0 through 5.5.79
Vulnerable Versions Count84 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-73344
United States1,474 websites



Germany346 websites
France218 websites
GB192 websites
Italy155 websites
Spain120 websites
Netherlands117 websites
Canada100 websites
Poland88 websites
Brazil64 websites

Website Distribution by TLD

Number of websites using CVE-2026-73344
.com1,608 websites
.org364 websites
.de189 websites
.it115 websites
.net106 websites
.co.uk106 websites
.nl97 websites
.fr76 websites
.ca61 websites
.pl59 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73344

Top websites that are affected by CVE-2026-73344. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*************.com Canada*,***
********.com Germany**,***
*******.com United States**,***
****.org United States**,***
***********.net France**,***
**********.com Canada**,***
*****.com United States**,***
**********.com United States**,***
***.org GB**,***
****.us United States**,***
See full domain list

FAQ

CVE-2026-73344 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wp Data Access
A total of 3,958 websites have been identified as vulnerable to CVE-2026-73344, based on global website indexing conducted by WebTechSurvey.
The Wp Data Access is affected by the CVE-2026-73344 vulnerability.
Wp Data Access versions up to and including 5.5.79 are vulnerable to CVE-2026-73344.