CVE-2023-0631SQL Injection in Paid Memberships PRO

CWE-89SQL Injection3 documents3 sources
Severity
8.8HIGHNVD
EPSS
74.0%
top 1.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 20

Description

The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
Paid Memberships Pro < 2.9.12 - Subscriber+ SQL Injection2023-03-20
GHSA
GHSA-c7j2-766v-p4pp: The Paid Memberships Pro WordPress plugin before 22023-03-20
CVE-2023-0631 — SQL Injection in Paid Memberships PRO | cvebase