The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
https://wpscan.com/vulnerability/323140b1-66c4-4e7d-85a4-1c922e40866f
https://plugins.trac.wordpress.org/changeset/2336019/events-manager