Executive brief
The WP Shortcut Link WordPress plugin, installed on websites to add shortcut links and advertisement banners, contains an SQL injection vulnerability in its unauthenticated AJAX action. Attackers can exploit this flaw without any login credentials to extract sensitive data directly from the website's database, including customer information and site configuration details.
Technical details
The plugin through version 1.2.0 fails to sanitize and escape user-supplied parameters before including them in SQL queries within an AJAX action handler. The vulnerability is accessible to unauthenticated users, eliminating the need for valid credentials. An attacker can craft a malicious HTTP request to the vulnerable AJAX endpoint with specially crafted SQL commands in the unsanitized parameter (specifically the 'url' parameter) to execute arbitrary SQL queries against the WordPress database. This enables extraction of sensitive data, potential data modification, or denial of service attacks. No known patch was available at the time of publication.
Affected products
- WP Shortcut Link WP Shortcut Link through 1.2.0
Timeline
- 2026-09-16: disclosed: Public disclosure via WPScan
- 2026-09-18: advisory: CVE-2026-87767 published