Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.
https://thehackernews.com/2025/03/hackers-exploit-wordpress-mu-plugins-to.html
https://wpscan.com/blog/new-malware-campaign-targets-wp-automatic-plugin/