WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
References
Configurations
History
No history.
Information
Published : 2017-11-02 16:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-16510
Mitre link : CVE-2017-16510
CVE.ORG link : CVE-2017-16510
JSON object : View
Products Affected
wordpress
- wordpress
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')