How To Find SQL Injection Vulnerabilities in WordPress Plugins and Themes

SQL Injection (SQLi), a vulnerability almost as old as database-driven web applications themselves (CWE-89), persists as a classic example of failing to neutralize user-supplied input before it’s used in a SQL query. So why does this well-understood vulnerability type continue to exist?

This post was originally published on Wordfence by Alex Thomas.

Follow us

Don't be shy, get in touch. We love meeting interesting people and making new friends.