Wordpress Alert: SQL injection in form plugins
A form lookup or submission filter is concatenated into SQL. Saved entries may be read or modified.
What it looks like
A form lookup or submission filter is concatenated into SQL.
Why it matters
Saved entries may be read or modified.
What to check
Check the installed form plugin's advisories and custom query code.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP SQL injection prevention.
- Categories: WordPress
- Tags: #WordPress Security, #Injection