Remediation Steps
Follow the steps below to remediate this finding on WordPress.
Use $wpdb->prepare() for all custom MySQL queries:
$results = $wpdb->get_results( $wpdb->prepare('SELECT * FROM wp_users WHERE user_login = %s', $username) );Ensure the WordPress database user only has the minimum required privileges.
Review plugins for raw SQL usage — replace with $wpdb->prepare() equivalents.