WordPress Core, the software used to run websites, is vulnerable to SQL Injection in versions up to 6.0.3. This means that an attacker can use a plugin or theme installed on a website to get access to data stored in the website’s database. This is due to the website not properly protecting itself when using “AND” and “OR” in a query.