The Testimonial Slider plugin up to and including 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).
slidervilla testimonial slider