PT-2026-1214 · WordPress · Team Wordpress
Alex Tselevich
·
Published
2026-01-05
·
Updated
2026-04-14
·
CVE-2025-14124
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Team WordPress plugin versions prior to 5.0.11
Description
The Team WordPress plugin does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action. This allows unauthenticated users to potentially execute SQL injection attacks. The issue is related to insufficient input validation before utilizing data within a SQL query. The vulnerable action is accessible through an AJAX request. A specific parameter is not adequately sanitized, leading to the potential for malicious code execution.
Recommendations
Update The Team WordPress plugin to version 5.0.11 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Team Wordpress