CVE-2026-16532

Summary

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

Affected Software

VendorProductVersion RangeStatus
UnknownLink Library0 < 7.9.3affected

Weaknesses

  • CWE-89 SQL Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: total

References