Skip to content

Known CVE

Team WordPress Plugin (TLP Team) <= 5.0.9 - SQL Injection

Team WordPress plugin <= 5.0.11 contains a SQL injection caused by improper sanitization and escaping of a parameter in an AJAX action accessible to unauthenticated users, letting remote attackers execute arbitrary SQL commands.

CVE-2025-14124

High2025CVSS 8.6CWE-89

cve2025 · sqli · wordpress · wp · wp-plugin · tlp-team

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website