Showing 2 vulnerabilities on this page for paid_memberships_pro

Signals CISA KEV Ransomware Nuclei
strangerstudios vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

strangerstudios paid_memberships_pro Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

CWE-89Jan 20, 20231 related artifact
CVSS9.8v3.1EPSS92.5%PoCs3SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

CWE-89Feb 7, 20221 related artifact
CVSS9.8v3.1EPSS81.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX