strangerstudios Vulnerabilities and Affected Products
Vulnerabilities associated with paid_memberships_pro.
Products
Clear product- Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions9 vulnerabilities
- Memberlite Shortcodes2 vulnerabilities
- paid_memberships_pro2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-23488CRITICAL | strangerstudios paid_memberships_pro Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route. | CVSS9.8v3.1 | EPSS92.5% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2021-25114CRITICAL | Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL InjectionThe Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection | CVSS9.8v3.1 | EPSS81.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |