{"id":2362797,"date":"2011-10-24T07:33:32","date_gmt":"2011-10-24T07:33:32","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/plugin-search-light-sql-exploit\/"},"modified":"2016-08-20T03:06:36","modified_gmt":"2016-08-20T03:06:36","slug":"plugin-search-light-sql-exploit","status":"closed","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/plugin-search-light-sql-exploit\/","title":{"rendered":"[Plugin: Search Light] Potential for SQL Attacks"},"content":{"rendered":"<p>Perhaps I have missed something; but there doesn&#8217;t seem to be any kind of input sanitisation going on. If you look at the <code>itsas_sqlWhere()<\/code> and <code>itsas_search()<\/code> functions, it seems that the SQL queries are being constructed WITHOUT any safe-guards against SQL injection attacks. <\/p>\n<p>No where is <code>$wpdb-&gt;prepare()<\/code> or <code>mysql_real_escape_string()<\/code> called.  If no sanitisation is present, this represents a massive security problem for the plugin users.<\/p>\n<p>https:\/\/wordpress.org\/extend\/plugins\/search-light\/<\/p>\n","protected":false},"template":"","class_list":["post-2362797","topic","type-topic","status-closed","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/2362797","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/2362797\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=2362797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}