Updated WordPress Plugin Security Testing Cheat Sheet (markdown)

Ryan Dewhurst
2021-01-04 14:11:49 +01:00
parent d90fb63a97
commit 38390cec1c

@@ -95,6 +95,8 @@ Note: Before WordPress 3.5 ```$wpdb->prepare``` could be used insecurely as you
```$wpdb->query( $wpdb->prepare( "INSERT INTO table (user, pass) VALUES ('$user', '$pass')" ) );```
Example regex: `wpdb->(query|get_var|get_row|get_col|get_results|replace)\((?!.*prepare).*\);`
### SQL Injection Tips
Unsafe escaping ('securing') API methods: