The Short URL WordPress plugin through 1.6.8 does not...
High severity
Unreviewed
Published
Jun 6, 2025
to the GitHub Advisory Database
•
Updated Jun 10, 2025
Description
Published by the National Vulnerability Database
Jun 6, 2025
Published to the GitHub Advisory Database
Jun 6, 2025
Last updated
Jun 10, 2025
The Short URL WordPress plugin through 1.6.8 does not properly sanitise and escape a parameter before using it in SQL statement, leading to a SQL injection exploitable by users with relatively low privilege on the site, like subscribers.
References