Unvaludated input in the 301 Redirects – Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its «Redirect From» column when importing a CSV file, allowing high privilege users to perform SQL injections.