CVE-2026-87767 PUBLISHED

WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url

Assigner: WPScan
Reserved: 09.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.

Product Status

Vendor Unknown
Product wp shortcut link and advertisement baner
Versions Default: unknown
  • affected from 0 to 1.2.0 (incl.)

Credits

  • Theo Antônio Da Fonseca finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE