The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.CreditsJoão Ramos MacielWPScanReferenceshttps://wpscan.com/vulnerability/eebacbae-4b25-45b5-96d9-f5ba28dfd825/