Known CVE
Team WordPress Plugin (TLP Team) <= 5.0.9 - SQL Injection
Team WordPress plugin <= 5.0.11 contains a SQL injection caused by improper sanitization and escaping of a parameter in an AJAX action accessible to unauthenticated users, letting remote attackers execute arbitrary SQL commands.
CVE-2025-14124
High2025CVSS 8.6CWE-89
cve2025 · sqli · wordpress · wp · wp-plugin · tlp-team
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website