Team WordPress plugin <= 5.0.11 contains a SQL injection caused by improper sanitization and escaping of a parameter in an AJAX action accessible to unauthenticated users, letting remote attackers execute arbitrary SQL commands.
id: CVE-2025-14124
info:
name: Team WordPress Plugin (TLP Team) <= 5.0.9 - SQL Injection
author
...