CVE-2025-14124

Team < 5.0.11 - Unauthenticated SQLi

The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.


We have discovered 2,493 live websites that are affected by CVE-2025-14124.

Run a Free Instant Scan




Affected Software

Product  Tlp Team
Category Wordpress Plugins
Vulnerable Domains2,493 live websites (59% of Tlp Team install base)
Vulnerable Versions
  • from 0 through 5.0.11
Vulnerable Versions Count53 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jan 5, 2026
  • Updated - Jan 5, 2026

Credits

  • Alex Tselevich (nos3curity) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2025-14124
United States756 websites



Germany290 websites
GB159 websites
India108 websites
France101 websites
Italy80 websites
Netherlands78 websites
Switzerland59 websites
Canada57 websites
Denmark54 websites

Website Distribution by TLD

Number of websites using CVE-2025-14124
.com805 websites
.org352 websites
.de169 websites
.co.uk85 websites
.nl70 websites
.it56 websites
.ch53 websites
.at50 websites
.fr44 websites
.net39 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14124

Top websites that are affected by CVE-2025-14124. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.***.***.com Singapore**,***
***********.com United States**,***
*****.org United States***,***
****************.fr United States***,***
********************.org United States***,***
****.pk Pakistan***,***
************.com United States***,***
***************.com GB***,***
******************.org United States***,***
*************.com GB***,***
See full domain list

FAQ

CVE-2025-14124 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Tlp Team
A total of 2,493 websites have been identified as vulnerable to CVE-2025-14124, based on global website indexing conducted by WebTechSurvey.
The Tlp Team is affected by the CVE-2025-14124 vulnerability.
Tlp Team versions up to 5.0.11 are vulnerable to CVE-2025-14124.
CVE-2025-14124 is resolved in version 5.0.11 of Tlp Team.