Description
The query-database ability passes a user-constructed $query variable directly into $wpdb->get_results() without preparation or escaping.
Affected lines
- Line 157:
$wpdb->get_results() with unescaped $query (assigned at line 154)
- Same line: no caching around the query
Action needed
This ability accepts SQL from the AI, which is already a sensitive operation. At minimum:
- Validate that the query is read-only (starts with
SELECT, does not contain INSERT, UPDATE, DELETE, DROP, ALTER, TRUNCATE)
- Use
$wpdb->prepare() where possible
- Add caching or document why it's skipped
- Consider a query length limit and timeout
PHPCS rules
WordPress.DB.DirectDatabaseQuery.DirectQuery (WARNING)
WordPress.DB.DirectDatabaseQuery.NoCaching (WARNING)
PluginCheck.Security.DirectDB.UnescapedDBParameter (WARNING)
Description
The query-database ability passes a user-constructed
$queryvariable directly into$wpdb->get_results()without preparation or escaping.Affected lines
$wpdb->get_results()with unescaped$query(assigned at line 154)Action needed
This ability accepts SQL from the AI, which is already a sensitive operation. At minimum:
SELECT, does not containINSERT,UPDATE,DELETE,DROP,ALTER,TRUNCATE)$wpdb->prepare()where possiblePHPCS rules
WordPress.DB.DirectDatabaseQuery.DirectQuery(WARNING)WordPress.DB.DirectDatabaseQuery.NoCaching(WARNING)PluginCheck.Security.DirectDB.UnescapedDBParameter(WARNING)