PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14601 Link Whisper CVE debrief

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. This vulnerability affects WordPress installations using the Link Whisper Free plugin, potentially impacting user data and database integrity. Users should review their plugin versions and user roles to assess exposure.

Vendor
Link Whisper
Product
Link Whisper Free WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-08-21
Advisory published
2026-08-21
Advisory updated
2026-08-21

Who should care

Users of Link Whisper Free WordPress plugin version before 0.9.7, especially those with Editor role or above, should prioritize patching and monitor for suspicious database queries. Additionally, security teams and vulnerability management teams should review and verify affected scope and severity, focusing on potential data breaches and unauthorized access.

Technical summary

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. This vulnerability can lead to potential data breaches and unauthorized access to sensitive information stored in the database. Defenders should prioritize patching and monitor for suspicious database queries to mitigate potential risks.

Defensive priority

Authenticated users with Editor role or above may inject SQL; prioritize patching and monitor for suspicious database queries.

Recommended defensive actions

  • Apply patch to Link Whisper Free WordPress plugin version 0.9.7 or later
  • Monitor database queries for suspicious activity
  • Restrict Editor role or above to necessary users only
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Evidence from WPScan indicates a SQL injection vulnerability in Link Whisper Free WordPress plugin before 0.9.7; verify affected versions and user roles with caution as source detail is limited. Defenders should review plugin versions, user roles, and database queries for potential suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T07:16:24.530Z and has not been modified since then.