WordPress NewStatPress 0.9.8 plugin contains a SQL injection vulnerability in includes/nsp_search.php. A remote authenticated user can execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.
View the template here CVE-2015-4062.yaml
References:
https://wordpress.org/plugins/newstatpress/changelog/