CVE-2016-10939
The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
7.2CVSS
7.5AI Score
0.001EPSS