Wordpress Alert: SQL injection in search filters

A plugin builds a database query from a search filter without safe parameterization. Attackers may read or change data under the vulnerable query's conditions.

What it looks like

A plugin builds a database query from a search filter without safe parameterization.

Why it matters

Attackers may read or change data under the vulnerable query's conditions.

What to check

Review custom SQL and use prepared statements for filter values.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP SQL injection prevention.