WordPress PayPal Pro plugin before 1.1.65 is susceptible to SQL injection via the ‘query’ parameter which allows for any unauthenticated user to perform SQL queries with the results output to a web page in JSON format.
View the template here CVE-2020-14092.yaml
References:
https://wordpress.dwbooster.com/forms/payment-form-for-paypal-pro