PatchSiren cyber security CVE debrief
CVE-2026-14601 Link Whisper CVE debrief
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. This vulnerability affects WordPress installations using the Link Whisper Free plugin, potentially impacting user data and database integrity. Users should review their plugin versions and user roles to assess exposure.
- Vendor
- Link Whisper
- Product
- Link Whisper Free WordPress plugin
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-26
Who should care
Users of Link Whisper Free WordPress plugin version before 0.9.7, especially those with Editor role or above, should prioritize patching and monitor for suspicious database queries. Additionally, security teams and vulnerability management teams should review and verify affected scope and severity, focusing on potential data breaches and unauthorized access.
Technical summary
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. This vulnerability can lead to potential data breaches and unauthorized access to sensitive information stored in the database. Defenders should prioritize patching and monitor for suspicious database queries to mitigate potential risks.
Defensive priority
Authenticated users with Editor role or above may inject SQL; prioritize patching and monitor for suspicious database queries.
Recommended defensive actions
- Apply patch to Link Whisper Free WordPress plugin version 0.9.7 or later
- Monitor database queries for suspicious activity
- Restrict Editor role or above to necessary users only
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Evidence from WPScan indicates a SQL injection vulnerability in Link Whisper Free WordPress plugin before 0.9.7; verify affected versions and user roles with caution as source detail is limited. Defenders should review plugin versions, user roles, and database queries for potential suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14601 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14601
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14601 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14601
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/d855373e-fb96-4c1d-a503-0ebe6d0ed9a0/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.