Mika discovered and reported this SQL Injection vulnerability in WordPress WP Pipes Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 1.4.0.