Skip to content

SQL injection risk in database-check.php #122

Description

@CoachBirgit

Description

The database check ability has an unescaped parameter passed directly into a SQL query, which is both a security risk and a Plugin Checker blocker.

Affected lines

  • Line 280: $where_clauses used in $wpdb->get_results() without escaping. The variable is assigned unsafely at line 275.
  • Line 285: $where_clauses used without $wpdb->prepare()
  • Line 286: $wpdb->prepare() called but with no valid placeholders in the query string

Additionally:

  • Line 501: Usage of meta_key flagged as a potentially slow query. Consider adding a database index or caching the result.

Action needed

Refactor the query construction at lines 275–286 to use $wpdb->prepare() with proper %s / %d placeholders. Never concatenate variables directly into SQL strings.

PHPCS rules

  • WordPress.DB.PreparedSQL.NotPrepared (ERROR)
  • PluginCheck.Security.DirectDB.UnescapedDBParameter (WARNING)
  • WordPress.DB.PreparedSQLPlaceholders.UnfinishedPrepare (WARNING)
  • WordPress.DB.SlowDBQuery.slow_db_query_meta_key (WARNING)

Activity

  1. added a commit that references this issue on May 12, 2026
    c8de658
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions