Collected research
Assorted WordPress DB prepare exploits
WordPress's prepare function accepted an array of replacements and undocumented placeholders such as %c and numbered ones, so user input shaped like a placeholder, or a string prepared twice, could break out of the query and inject SQL. Version 4.8.2 restricted placeholders and broke plugins; 4.8.3 landed the balanced fix.
Record
- Published by
- Making WordPress Secure
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Making WordPress Secure, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .