PT-2026-1214 · WordPress · Team Wordpress

Alex Tselevich

·

Published

2026-01-05

·

Updated

2026-04-14

·

CVE-2025-14124

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Team WordPress plugin versions prior to 5.0.11
Description The Team WordPress plugin does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action. This allows unauthenticated users to potentially execute SQL injection attacks. The issue is related to insufficient input validation before utilizing data within a SQL query. The vulnerable action is accessible through an AJAX request. A specific parameter is not adequately sanitized, leading to the potential for malicious code execution.
Recommendations Update The Team WordPress plugin to version 5.0.11 or later.

Exploit

Fix

Related Identifiers

CVE-2025-14124

Affected Products

Team Wordpress