Unescaped parameter $sql used in $wpdb->query($this->wpdb->prepare( $sql, ...$args ))\n$sql assigned unsafely at line 23:\n $sql = "\n UPDATE {$this->wpdb->posts}\n SET post_status = %s\n WHERE ID IN ($placeholders)\n "
Unescaped parameter call_user_func_array( array( $wpdb, 'prepare' ), $args ) ) used in $wpdb->query(call_user_func_array( array( $wpdb, 'prepare' ), $args ))
Affected Plugins
Plugins that have instances of this rule violation