PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14601 Link Whisper CVE debrief

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. This vulnerability affects WordPress installations using the Link Whisper Free plugin, potentially impacting user data and database integrity. Users should review their plugin versions and user roles to assess exposure.

Vendor
Link Whisper
Product
Link Whisper Free WordPress plugin
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-26
Advisory published
2026-08-21
Advisory updated
2026-08-26

Who should care

Users of Link Whisper Free WordPress plugin version before 0.9.7, especially those with Editor role or above, should prioritize patching and monitor for suspicious database queries. Additionally, security teams and vulnerability management teams should review and verify affected scope and severity, focusing on potential data breaches and unauthorized access.

Technical summary

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. This vulnerability can lead to potential data breaches and unauthorized access to sensitive information stored in the database. Defenders should prioritize patching and monitor for suspicious database queries to mitigate potential risks.

Defensive priority

Authenticated users with Editor role or above may inject SQL; prioritize patching and monitor for suspicious database queries.

Recommended defensive actions

  • Apply patch to Link Whisper Free WordPress plugin version 0.9.7 or later
  • Monitor database queries for suspicious activity
  • Restrict Editor role or above to necessary users only
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Evidence from WPScan indicates a SQL injection vulnerability in Link Whisper Free WordPress plugin before 0.9.7; verify affected versions and user roles with caution as source detail is limited. Defenders should review plugin versions, user roles, and database queries for potential suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14601 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14601

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14601 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14601

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.