Unescaped parameter $column used in $wpdb->get_row($wpdb->prepare( "\n\t\t\tSELECT *\n\t\t\tFROM {$table}\n\t\t\tWHERE {$column} LIKE %s\n\t\t\tORDER BY {$key_column} ASC\n\t\t\tLIMIT 1\n\t\t", $key ))\n$column assigned unsafely at line 265:\n $column = 'meta_key'\n$key_column assigned unsafely at line 266:\n $key_column = 'meta_id'\n$value_column assigned unsafely at line 267:\n $value_column = 'meta_value'\n$key assigned unsafely at line 270:\n $key = $wpdb->esc_like( $this->identifier . '_batch_' ) . '%'
Unescaped parameter $custom_table_name used in $wpdb->get_row("SELECT COUNT(*) as item_count FROM {$custom_table_name}")\n$custom_table_name assigned unsafely at line 631:\n $custom_table_name = $queue_table_storage->table_name\n$queue_table_storage->table_name used without escaping.
Unescaped parameter $custom_table_name used in $wpdb->query("DELETE FROM {$custom_table_name}")\n$custom_table_name assigned unsafely at line 631:\n $custom_table_name = $queue_table_storage->table_name\n$queue_table_storage->table_name used without escaping.
Unescaped parameter $id used in $wpdb->get_results("SELECT $id, meta_key, meta_value, meta_id FROM $table WHERE $id IN ( " . implode( ',', wp_parse_id_list( $ids ) ) . ' )' .\n\t\t\t\t" AND meta_key IN ( $private_meta_whitelist_sql ) ")\n$id assigned unsafely at line 595:\n $id = $meta_type . '_id'\n$table assigned unsafely at line 594:\n $table = _get_meta_table( $meta_type )\n$meta_type used without escaping.
Affected Plugins
Plugins that have instances of this rule violation
Unescaped parameter $id used in $wpdb->get_results("SELECT MAX({$id}) as max, MIN({$id}) as min, COUNT({$id}) as count FROM {$table} WHERE {$where_sql}")\n$id assigned unsafely at line 311:\n $id = 'term_id'\n$table assigned unsafely at line 308:\n $table = $module->table()\n$where_sql assigned unsafely at line 313:\n $where_sql = $module->get_where_sql( array() )\n$module assigned unsafely at line 303:\n $module = Modules::get_module( $type )\n$type used without escaping.