Use `$wpdb->prepare` for dynamic WordPress SQL
WordPress SQL calls should not interpolate request values directly into query strings.
#Metadata
#Why it matters
Dynamic SQL without `$wpdb->prepare` enables injection and unauthorized data access/manipulation.
#Remediation
Build SQL through `$wpdb->prepare` placeholders and sanitize scalar inputs before passing them to query execution calls.
#Repository path
The generated metadata points to critiq-rules/libs/rules/catalog/rules/php/php.security.wordpress-unprepared-sql.rule.yaml.