PatchSiren cyber security CVE debrief
CVE-2026-14601 Link Whisper CVE debrief
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. This vulnerability affects WordPress installations using the Link Whisper Free plugin, potentially impacting user data and database integrity. Users should review their plugin versions and user roles to assess exposure.
- Vendor
- Link Whisper
- Product
- Link Whisper Free WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-08-21
Who should care
Users of Link Whisper Free WordPress plugin version before 0.9.7, especially those with Editor role or above, should prioritize patching and monitor for suspicious database queries. Additionally, security teams and vulnerability management teams should review and verify affected scope and severity, focusing on potential data breaches and unauthorized access.
Technical summary
The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. This vulnerability can lead to potential data breaches and unauthorized access to sensitive information stored in the database. Defenders should prioritize patching and monitor for suspicious database queries to mitigate potential risks.
Defensive priority
Authenticated users with Editor role or above may inject SQL; prioritize patching and monitor for suspicious database queries.
Recommended defensive actions
- Apply patch to Link Whisper Free WordPress plugin version 0.9.7 or later
- Monitor database queries for suspicious activity
- Restrict Editor role or above to necessary users only
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Evidence from WPScan indicates a SQL injection vulnerability in Link Whisper Free WordPress plugin before 0.9.7; verify affected versions and user roles with caution as source detail is limited. Defenders should review plugin versions, user roles, and database queries for potential suspicious activity.
Official resources
-
CVE-2026-14601 CVE record
CVE.org
-
CVE-2026-14601 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T07:16:24.530Z and has not been modified since then.