The wp-all-import plugin before 3.2.5 for WordPress has blind SQL injection.
Published August 20, 2019.
Soflyy WP All Import