WordPress Core, up to version 6.0.2, is vulnerable to a form of attack called SQL Injection. This type of attack can be used by anyone who is logged in to WordPress and has a high-level of access, such as an editor or an administrator. In some cases, users with lower-level privileges may also be able to exploit this vulnerability if a plugin or theme does not check for an unescaped user supplied value when using the get_bookmarks function.