← WordPress Vulnerabilities
WordPress security by component

CF Internal Link Shortcode

CF Internal Link Shortcode is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jan 11, 2025; the highest CVE/CNA score is 7.5.

Plugin slug: internal-link-shortcode

CVE-2024-12404: CF Internal Link Shortcode: SQL injection

CF Internal Link Shortcode is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.

PublishedJan 11, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 11, 2025 CVE-2024-12404
CF Internal Link Shortcode: SQL injection
CF Internal Link Shortcode is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending