The wp-business-intelligence-lite plugin prior to 1.6.3 for WordPress has SQL injection.
wpbusinessintelligence wp business intelligence