Unescaped parameter $column_name used in $wpdb->get_var($wpdb->prepare( "SELECT {$column_name} FROM {$wpdb->posts} WHERE ID=%d AND post_type=%s", $action_id, self::POST_TYPE ))
Unescaped parameter $query used in $wpdb->get_var($query)\n$query assigned unsafely at line 260:\n $query = $wpdb->prepare( $query, $args )\n$query assigned unsafely at line 258:\n $query .= " ORDER BY scheduled_date_gmt $order LIMIT 1"\n$order assigned unsafely at line 254:\n $order = 'DESC'
Unescaped parameter $query used in $wpdb->get_var($query)\n$query assigned unsafely at line 276:\n $query = $wpdb->prepare( $query, $args )\n$query assigned unsafely at line 259:\n $query .= " AND p.post_status=%s"\n$params['status'] used without escaping.
Unescaped parameter $query_count used in $wpdb->get_var($query_count)\n$query_count assigned unsafely at line 433:\n $query_count = "SELECT COUNT({$this->ID}) FROM {$this->table_name} {$where}"\n$where assigned unsafely at line 426:\n $where = ''\n$sql assigned unsafely at line 429:\n $sql = "SELECT $columns FROM {$this->table_name} {$where} {$order} {$limit} {$offset}"\n$columns assigned unsafely at line 421:\n $columns = '`' . implode( '`, `', $this->get_table_columns() ) . '`'\n$order assigned unsafely at line 416:\n $order = $this->get_items_query_order()\n$limit assigned unsafely at line 414:\n $limit = $this->get_items_query_limit()\n$offset assigned unsafely at line 415:\n $offset = $this->get_items_query_offset()
Affected Plugins
Plugins that have instances of this rule violation
Unescaped parameter $query_in used in $wpdb->query($wpdb->prepare( \t\t\t\t\t"UPDATE {$wpdb->actionscheduler_actions} SET status = %s WHERE action_id IN {$query_in}",\n\t\t\t\t\t$parameters\n\t\t\t\t))\n$query_in assigned unsafely at line 535:\n $query_in = '(' . implode( ',', $format ) . ')'\n$parameters assigned unsafely at line 536:\n $parameters = $action_ids\n$action_ids assigned unsafely at line 529:\n $action_ids = $this->query_actions( $query_args )\n$query_args assigned unsafely at line 520:\n $query_args = wp_parse_args(\n\t\t\t$query_args,\n\t\t\t[\n\t\t\t\t'per_page' => 1000,\n\t\t\t\t'status' => self::STATUS_PENDING,\n\t\t\t]\n\t\t)