The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins and above to perform SQL injection attacks
https://wpscan.com/vulnerability/1b355399-e92b-46aa-ada1-95e99fc03976/