{"id":4471545,"date":"2014-01-05T03:56:45","date_gmt":"2014-01-05T03:56:45","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/sql-exploit\/"},"modified":"2016-08-21T14:25:06","modified_gmt":"2016-08-21T14:25:06","slug":"sql-exploit","status":"closed","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/sql-exploit\/","title":{"rendered":"SQL exploit"},"content":{"rendered":"<p>Hi,<\/p>\n<p>I am looking through your code to make a similar plugin, and so am looking over everything, and found that you have some significant issues with your plugin.<\/p>\n<p>I only tried deleting data from your plugin, e.g. I can erase all records by submitting a simple request, but I assume I could also do anything I wanted to any table in the database.<\/p>\n<p>You shouldn&#8217;t ever take input from a user and put it into a database.  That *always* means someone can hack into your database.<\/p>\n<p>Here are a couple links for you to check things out.<\/p>\n<p>http:\/\/en.wikipedia.org\/wiki\/SQL_injection<\/p>\n<p>http:\/\/www.flippercode.com\/how-to-hack-wordpress-site-using-sql-injection<\/p>\n<p>https:\/\/wordpress.org\/plugins\/kento-like-post\/<\/p>\n","protected":false},"template":"","class_list":["post-4471545","topic","type-topic","status-closed","hentry","topic-tag-sql-injection"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/4471545","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/4471545\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=4471545"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}