Critical severity9.8NVD Advisory· Published Nov 2, 2017· Updated May 13, 2026
CVE-2017-16510
CVE-2017-16510
Description
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
Affected products
1- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*Range: <=4.8.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- github.com/WordPress/WordPress/commit/a2693fd8602e3263b5925b9d799ddd577202167dnvdIssue TrackingPatchVendor Advisory
- www.securityfocus.com/bid/101638nvdThird Party AdvisoryVDB Entry
- blog.ircmaxell.com/2017/10/disclosure-wordpress-wpdb-sql-injection-technical.htmlnvdIssue TrackingThird Party Advisory
- codex.wordpress.org/Version_4.8.3nvdIssue TrackingVendor Advisory
- wordpress.org/news/2017/10/wordpress-4-8-3-security-release/nvdIssue TrackingVendor Advisory
- wpvulndb.com/vulnerabilities/8941nvdIssue TrackingVendor Advisory
- lists.debian.org/debian-lts-announce/2017/11/msg00003.htmlnvd
- www.debian.org/security/2018/dsa-4090nvd
News mentions
0No linked articles in our index yet.