[wp-trac] [WordPress Trac] #57678: Missing use of placeholders and $wpdb->prepare()

WordPress Trac noreply at wordpress.org
Wed Feb 15 14:14:38 UTC 2023


#57678: Missing use of placeholders and $wpdb->prepare()
-----------------------------------------------+---------------------------
 Reporter:  mahekkalola                        |       Owner:  (none)
     Type:  defect (bug)                       |      Status:  new
 Priority:  normal                             |   Milestone:  Awaiting
                                               |  Review
Component:  Query                              |     Version:
 Severity:  major                              |  Resolution:
 Keywords:  has-patch close reporter-feedback  |     Focuses:  coding-
                                               |  standards
-----------------------------------------------+---------------------------

Comment (by chiragrathod103):

 @johnbillion Thanks for the response.

 Let's assume WP was already installed and by mistake config file was
 removed, and some created new config files, and the user added the wrong
 prefix in the config file then it will get this one screen when we use the
 "query" function ( https://prnt.sc/3mounErt7b0U )

 But if we will use the "prepare" function then it will prevent users let
 them knowing that they are using incorrect prefix as shown in this
 screenshot( https://prnt.sc/CY0_e51YsVI5 )

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/57678#comment:3>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list