Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.
https://wpscan.com/vulnerability/19800898-d7b6-4edd-887b-dac3c0597f14