CVE-2021-20678: SQL Injection
Published Mar 18, 2021
·Updated
SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
Affected Software
2 affected components
Paidmembershipspro Paid Memberships Pro Wordpress<2.5.6
Strangerstudios Paid Memberships Pro Wordpress<2.5.6
Event History
Mar 18, 2021
CVE Published
via MITRE·12:56 AM
Data Sourced
via MITRE·12:56 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-20678?
CVE-2021-20678 is a SQL injection vulnerability in the Paid Memberships Pro plugin for WordPress, versions prior to 2.5.6.
2
How can an attacker exploit CVE-2021-20678?
An attacker can exploit CVE-2021-20678 by sending specially crafted SQL queries, which can allow them to execute arbitrary SQL commands.
3
What is the severity of CVE-2021-20678?
CVE-2021-20678 has a severity score of 8.8 (high).
4
Which versions of Paid Memberships Pro are affected by CVE-2021-20678?
Versions of Paid Memberships Pro prior to 2.5.6 are affected by CVE-2021-20678.
5
How can I fix CVE-2021-20678?
To fix CVE-2021-20678, update Paid Memberships Pro to version 2.5.6 or later.