PT-2026-1214 · WordPress · Team Wordpress

·

CVE-2025-14124

·

Published

2026-01-05

·

Updated

2026-04-14

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Team WordPress plugin versions prior to 5.0.11
Description The Team WordPress plugin does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action. This allows unauthenticated users to potentially execute SQL injection attacks. The issue is related to insufficient input validation before utilizing data within a SQL query. The vulnerable action is accessible through an AJAX request. A specific parameter is not adequately sanitized, leading to the potential for malicious code execution.
Recommendations Update The Team WordPress plugin to version 5.0.11 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-14124

Affected Products

Team Wordpress