CVE-2021-25114: Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discountcode in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25114?
CVE-2021-25114 is a vulnerability in the Paid Memberships Pro WordPress plugin before version 2.6.7 that allows SQL injection.
How severe is CVE-2021-25114?
CVE-2021-25114 has a severity rating of 9.8 (Critical).
Which software versions are affected by CVE-2021-25114?
Versions of the Paid Memberships Pro WordPress plugin between 2.4 and 2.6.6 are affected by CVE-2021-25114.
How can I fix CVE-2021-25114?
To fix CVE-2021-25114, update to version 2.6.7 of the Paid Memberships Pro WordPress plugin.
Where can I find more information about CVE-2021-25114?
You can find more information about CVE-2021-25114 on the WPScan vulnerability page (https://wpscan.com/vulnerability/6c25a5f0-a137-4ea5-9422-8ae393d7b76b) and the Paid Memberships Pro website (https://www.paidmembershipspro.com/pmpro-update-2-6-7-security-release/).