CVE-2022-46860: SQL Injection Lets Hackers Hijack WordPress Short URLs
Over 43% of the web runs WordPress, and CVE-2022-46860 just handed hackers a loaded gun. A simple SQL injection in the Short URL plugin could let anyone steal your data.
theAIcatchupApr 08, 20263 min read
⚡ Key Takeaways
CVE-2022-46860 enables unauthenticated SQL injection in KaizenCoders Short URL, risking full database compromise.𝕏
43,000+ installs make this a widespread threat; no patch available yet.𝕏
Deactivate now—history shows unpatched WordPress plugin flaws lead to mass exploits.𝕏
The 60-Second TL;DR
CVE-2022-46860 enables unauthenticated SQL injection in KaizenCoders Short URL, risking full database compromise.
43,000+ installs make this a widespread threat; no patch available yet.
Deactivate now—history shows unpatched WordPress plugin flaws lead to mass exploits.