PatchSiren

Link Whisper CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Link Whisper CVE published 2026-08-21

CVE-2026-14601

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with the Editor role or above to perform SQL injection attacks. This vulnerability affects WordPress installations using the Link Whisper Free plugin, potentially impacting user data and database integrity. Users should review their plugin versi [truncated]