In **lib/post-type.php** and **lib/taxonomy.php**, the direct sql queries need to be parameterized to protect against attacks.