First published: Mon Mar 20 2023(Updated: )
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Strangerstudios Paid Memberships Pro | <2.9.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-0631.
The severity of CVE-2023-0631 is high.
The Paid Memberships Pro WordPress plugin before version 2.9.12 is affected by CVE-2023-0631.
CVE-2023-0631 allows subscribers to render shortcodes that can concatenate attributes directly into an SQL query, potentially leading to SQL injection attacks.
Yes, upgrading to version 2.9.12 of the Paid Memberships Pro WordPress plugin will fix CVE-2023-0631.