The Mobile builder WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
https://wpscan.com/vulnerability/6338f3af-1702-4095-a60e-a6e3dff09018/