Injection

Guide tag · 10 matching pages

Wordpress Alert: SQL injection in sorting parameters

A user-controlled sort field is inserted into a database query. The query structure may be altered if the field is not allowlisted.

Wordpress Alert: SQL injection in search filters

A plugin builds a database query from a search filter without safe parameterization. Attackers may read or change data under the vulnerable query's conditions.

Wordpress Alert: SQL injection in reporting dashboards

Report filters become part of an unsafe SQL query. Sensitive records may be exposed or reports altered.

Wordpress Alert: SQL injection in form plugins

A form lookup or submission filter is concatenated into SQL. Saved entries may be read or modified.

Wordpress Alert: SQL injection in booking plugins

A booking search or calendar parameter reaches an unsafe query. Reservation and customer data may be exposed.

Wordpress Alert: Spreadsheet formula injection in exported CSV files

A form or report export begins a cell with formula syntax. Opening the CSV in spreadsheet software may execute a formula.

Wordpress Alert: Server-side template injection

A theme or builder evaluates user-controlled text as a template. Template capabilities may disclose data or run unintended operations.

Wordpress Alert: PHP object injection through unsafe deserialization

A plugin unserializes untrusted input into PHP objects. Available object behaviors may be abused, sometimes with severe consequences.

Wordpress Alert: Email-header injection in contact forms

A contact form accepts newline or header syntax in email fields. Messages may gain unintended recipients or headers.

Wordpress Alert: Command injection in backup tools

A backup option is passed unsafely to a system command. The server may execute unintended commands.