The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated users, such as subscriber to perform SQLI attacksCreditsYousof NahyaWPScanReferenceshttps://wpscan.com/vulnerability/aec53f87-6500-4c8a-925a-146be61bbabf/