WordPress Vulnerabilities
WP < 6.0.2 - SQLi via Link API
Description
The get_bookmarks() function does not validate and escape a parameter before using it in a SQL statement, which could lead to SQL injection when user input is passed to it directly or via wp_list_bookmarks() for example.
Affects WordPress
References
Classification
Type
SQLI
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
FVD
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2022-08-30 (about 3 years ago)
Added
2022-08-30 (about 3 years ago)
Last Updated
2022-09-07 (about 3 years ago)