CVE-2023-23488

CRITICAL EXPLOITED NUCLEI

Strangerstudios Paid Memberships Pro < 2.9.8 - SQL Injection

Title source: rule

Description

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

Exploits (6)

nomisec SCANNER 1 stars
by cybfar · remote
https://github.com/cybfar/CVE-2023-23488-pmpro-2.8
nomisec WORKING POC
by long-rookie · poc
https://github.com/long-rookie/CVE-2023-23488-PoC
exploitdb SCANNER VERIFIED
by r3nt0n · pythonwebappsphp
https://www.exploit-db.com/exploits/51235
vulncheck_xdb WRITEUP
remote
https://github.com/Manh130902/wordpress
metasploit WORKING POC
by h00die, Joshua Martinelle · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wp_paid_membership_pro_code_sqli.rb

Nuclei Templates (1)

WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection
CRITICALVERIFIEDby dwisiswant0
Shodan: http.html:/wp-content/plugins/paid-memberships-pro/
FOFA: body=/wp-content/plugins/paid-memberships-pro/

Scores

CVSS v3 9.8
EPSS 0.8418
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2023-01-14

Classification

CWE
CWE-89
Status published

Affected Products (1)

strangerstudios/paid_memberships_pro < 2.9.8

Timeline

Published Jan 20, 2023
Tracked Since Feb 18, 2026