Unescaped parameter $AND_NOT_IN used in $wpdb->get_col("SELECT aid FROM $wpdb->democracy_a WHERE qid = $poll_id $AND_NOT_IN")\n$AND_NOT_IN assigned unsafely at line 450:\n $AND_NOT_IN = $ids ? sprintf( "AND aid NOT IN (" . implode( ',', $ids ) . ")" ) : ''\n$ids assigned unsafely at line 444:\n $ids[] = $aid\n$aid assigned unsafely at line 422:\n $aid => \n$answ_row assigned unsafely at line 423:\n $answ_row = $wpdb->get_row( "SELECT * FROM $wpdb->democracy_a WHERE aid = " . (int) $aid )
Unescaped parameter $AND_clause used in $wpdb->query($wpdb->prepare(\n\t\t\t"UPDATE $wpdb->democracy_a SET votes = (votes+1) WHERE qid = %d $AND_clause", $poll->id\n\t\t))\n$AND_clause assigned unsafely at line 116:\n $AND_clause = ' AND aid IN (' . $aids . ')'\n$aids assigned unsafely at line 115:\n $aids = implode( ',', $aids )\n$aids assigned unsafely at line 112:\n $aids = array_slice( $aids, 0, $poll->multiple )\n$aids assigned unsafely at line 104:\n $aids = reset( $aids )\n$aids assigned unsafely at line 96:\n $aids = array_filter( $aids )\n$aids assigned unsafely at line 91:\n $aids[] = $aid\n$poll->multiple used without escaping.\n$aid assigned unsafely at line 90:\n $aid = $this->insert_democratic_answer( $new_free_answer \n$new_free_answer assigned unsafely at line 78:\n $new_free_answer = $id\n$aids[] used without escaping.\n$id used without escaping.
Affected Plugins
Plugins that have instances of this rule violation
Unescaped parameter $WHERE used in $wpdb->get_var("SELECT count(*) FROM $wpdb->democracy_log $WHERE")\n$WHERE assigned unsafely at line 100:\n $WHERE .= ' AND 0 '\n$WHERE assigned unsafely at line 97:\n $WHERE .= " AND qid IN ($qid_IN) AND ( aids RLIKE '(^|,)($aid_OR)(,|$)' )"\n$per_page assigned unsafely at line 72:\n $per_page = get_user_meta( get_current_user_id(), get_current_screen()->get_option( 'per_page', 'option' ), true ) ?: 20\n$qid_IN assigned unsafely at line 95:\n $qid_IN = implode( ',', wp_list_pluck( $aqids, 'qid' ) )\n$aid_OR assigned unsafely at line 96:\n $aid_OR = implode( '|', wp_list_pluck( $aqids, 'aid' ) )\n$aqids assigned unsafely at line 93:\n $aqids = $wpdb->get_results( "SELECT DISTINCT aid, qid FROM $wpdb->democracy_a WHERE added_by LIKE '%-new'" )
Unescaped parameter $aid used in $wpdb->get_row("SELECT * FROM $wpdb->democracy_a WHERE aid = " . (int) $aid)\n$aid assigned unsafely at line 422:\n $aid => \n$answ_row assigned unsafely at line 423:\n $answ_row = $wpdb->get_row( "SELECT * FROM $wpdb->democracy_a WHERE aid = " . (int) $aid )
Unescaped parameter $aid used in $wpdb->get_row("SELECT * FROM $wpdb->democracy_a WHERE aid = " . (int) $aid)\n$aid used without escaping.