Web Hack List

Collected research

Assorted WordPress DB prepare exploits

WordPress's prepare function accepted an array of replacements and undocumented placeholders such as %c and numbered ones, so user input shaped like a placeholder, or a string prepared twice, could break out of the query and inject SQL. Version 4.8.2 restricted placeholders and broke plugins; 4.8.3 landed the balanced fix.

Record

Published by
Making WordPress Secure
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Making WordPress Secure, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .