CVE-2025-14124: Unknown Team
High severity, CVSS 8.6. EPSS: 1.7% chance of exploitation in the next 30 days.
The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
Affected products
- Unknown Team: before 5.0.11 (fixed in 5.0.11)
Published 2026-01-05. Last modified 2026-06-17.