Wordpress Alert: SQL injection in sorting parameters

A user-controlled sort field is inserted into a database query. The query structure may be altered if the field is not allowlisted.

What it looks like

A user-controlled sort field is inserted into a database query.

Why it matters

The query structure may be altered if the field is not allowlisted.

What to check

Allowlist sortable columns and audit custom query construction.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP SQL injection prevention.