云虫漏洞库

CVE-2026-3235 - The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app containers by exploiting a mismatch between the authorization check (performed against app_id) and data retrieval (performed using cnt_id without verifying container ownershi - 漏洞详情

漏洞编号:CVE-2026-3235

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-3235

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-639

发布/更新时间:2026-08-26 / 2026-08-28

漏洞描述

The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app containers by exploiting a mismatch between the authorization check (performed against app_id) and data retrieval (performed using cnt_id without verifying container ownership).

相关链接

相关漏洞

« 返回首页