The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in...
https://plugins.trac.wordpress.org/changeset/3461591/geo-mashup
https://plugins.trac.wordpress.org/browser/geo-mashup/tags/1.13.17/geo-mashup-db.php#L1701
https://plugins.trac.wordpress.org/browser/geo-mashup/tags/1.13.17/geo-mashup-db.php#L1530