WordPress PayPal Pro plugin before 1.1.65 is susceptible to SQL injection via the 'query' parameter which allows for any unauthenticated user to perform SQL queries with the results output to a web page in JSON format.
id: CVE-2020-14092
info:
name: WordPress PayPal Pro <1.1.65 - SQL Injection
author: princechadd
...