Wordpress Alert: SQL injection in search filters
A plugin builds a database query from a search filter without safe parameterization. Attackers may read or change data under the vulnerable query's conditions.
What it looks like
A plugin builds a database query from a search filter without safe parameterization.
Why it matters
Attackers may read or change data under the vulnerable query's conditions.
What to check
Review custom SQL and use prepared statements for filter values.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP SQL injection prevention.
- Categories: WordPress
- Tags: #WordPress Security, #Injection