The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.
https://www.wordfence.com/blog/2017/10/zero-day-vulnerability-ultimate-form-builder-lite/
https://wpvulndb.com/vulnerabilities/8935
https://wordpress.org/plugins/ultimate-form-builder-lite/#developers