CVE-2026-14601: Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter
Published Aug 21, 2026
·Updated
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks.
Affected Software
0 affected components
Event History
Aug 21, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An authenticated WordPress user with the Editor role or a higher-privileged role can exploit it. Unauthenticated visitors are not identified as able to exploit it in the available information.
2
Which deployments are affected?
Link Whisper Free versions before 0.9.7 are affected. The available information does not state whether any particular WordPress configuration changes exposure.
3
What should teams do to remediate it?
Update Link Whisper Free to version 0.9.7 or later. The provided information does not describe a temporary mitigation if updating is not immediately possible.