Description
The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
Published: 2026-09-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive data exposure through unauthenticated SQL injection
Action: Immediate patch
AI Analysis

Impact

The WordPress plugin 'WP Shortcut Link' (advertisement banner) up to version 1.2.0 fails to sanitize an input parameter that is then concatenated into an SQL query within an AJAX action. Because this action is available to all visitors, attackers can inject SQL through a crafted URL and retrieve arbitrary data from the database. The flaw permits compromise of confidentiality and potentially integrity, but is not documented as a remote code execution vulnerability.

Affected Systems

Any WordPress installation that has the 'WP Shortcut Link' plugin version 1.2.0 or earlier installed is affected. No other vendors or versions are listed, and the vulnerability is specifically tied to the plugin's AJAX endpoint.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity impact. The EPSS score is lower than 1%, suggesting a low probability of exploitation in the wild, and the flaw is not present in CISA’s KEV catalog. Nevertheless, because the endpoint is unauthenticated, the attack vector is straightforward: send a crafted request to the AJAX action to extract data. Effective exploitation requires the code to reach the vulnerable query, which is a direct input concatenation vulnerable to SQL injection.

Generated by OpenCVE AI on September 19, 2026 at 19:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Shortcut Link to a version newer than 1.2.0 that includes input sanitization for the AJAX parameter.
  • If an update cannot be applied immediately, disable or uninstall the plugin to eliminate the vulnerable AJAX endpoint.
  • Implement web application firewall rules that detect and block SQL injection patterns directed at the plugin’s AJAX action.

Generated by OpenCVE AI on September 19, 2026 at 19:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions wp Shortcut Link
Vendors & Products Wordpress-extensions
Wordpress-extensions wp Shortcut Link

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
Title WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url
References

Subscriptions

Wordpress-extensions Wp Shortcut Link
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T11:10:56.495Z

Reserved: 2026-09-09T08:08:42.700Z

Link: CVE-2026-87767

cve-icon Vulnrichment

Updated: 2026-09-18T11:03:15.563Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T06:16:40.307

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-87767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:21:53Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')