The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection.
https://wpscan.com/vulnerability/527a59cf-c7a3-4cf0-85f2-378c62eb7fce/