CVE-2017-16510: WordPress
Critical severity, CVSS 9.8. EPSS: 6.7% chance of exploitation in the next 30 days.
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
Affected products
- WordPress WordPress: up to and including 4.8.2
Published 2017-11-02. Last modified 2026-06-17.