Unescaped parameter $posts used in $wpdb->get_col(sprintf( "SELECT meta_value FROM {$wpdb->postmeta} WHERE meta_key = '_thumbnail_id' AND post_id IN(%s)", implode(',', $posts) ))\n$posts assigned unsafely at line 92:\n $posts = array_filter( $wpdb->get_col( $query ) )\n$query used without escaping.
Unescaped parameter $q used in $wpdb->get_col($q)\n$q assigned unsafely at line 109:\n $q = str_replace( 'SELECT ID FROM ', 'SELECT post_content FROM ', $query ) . ' AND post_content REGEXP "((wp-image-|wp-att-)[0-9][0-9]*)|\\\\\\[(gallery|playlist) |<!-- wp:(gallery|audio|image|video) |href=|src="' \n$query used without escaping.
Unescaped parameter $q used in $wpdb->get_results($q)\n$q assigned unsafely at line 197:\n $q = sprintf( "SELECT post_id, meta_key, meta_value FROM {$wpdb->postmeta} WHERE meta_key IN('_wp_attached_file', '_wp_attachment_metadata') AND post_id IN(%s)", implode( ',', $chunk ) )\n$chunk assigned unsafely at line 195:\n $chunk = array_slice( $attachment_ids, $i * 1000, 1000 )\n$attachment_ids assigned unsafely at line 192:\n $attachment_ids = array_keys( $attachments )\n$attachments used without escaping.
Unescaped parameter $query used in $wpdb->get_col($query)\n$query used without escaping.