What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a through <= 2.1.7.
Explanation of Vulnerability in Simple Terms
02Summary
BetterLinks versions up to 2.1.7 contain a SQL injection vulnerability in a high-privilege function. An authenticated administrator can craft malicious input to read sensitive data from the site database, including user credentials and configuration. The vulnerability requires admin access and does not allow data modification or site takeover, but exposes confidential information.
What an attacker can do
03Attacker Capabilities
Read sensitive data from the site database, including user information and site configuration.
Potential impact on your site
04Site Impact
If a malicious admin account exists, attackers can extract user passwords, email addresses, and other database records.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the WordPress site.
Key dates
06Disclosure timeline
November 4, 2024
CVE published
May 11, 2026
Record updated