CVE-2026-87767
WP Shortcut Link <= 1.2.0 - Unauthenticated SQL Injection via url
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a parameter before using it in a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database.
| Vendor | unknown |
| Product | wp shortcut link and advertisement baner |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp shortcut link and advertisement baner
Be the first to know when new unknown vulnerabilities affecting unknown wp shortcut link and advertisement baner are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / wp shortcut link and advertisement baner
0 ≤ 1.2.0
References
Credits
Theo Antônio Da Fonseca WPScan