CVE-2023-0631: Paid Memberships Pro < 2.9.12 - Subscriber+ SQL Injection
Published Mar 20, 2023
·Updated
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
Affected Software
1 affected component
Strangerstudios Paid Memberships Pro Wordpress<2.9.12
Event History
Mar 20, 2023
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-0631.
2
What is the severity of CVE-2023-0631?
The severity of CVE-2023-0631 is high.
3
Which software is affected by CVE-2023-0631?
The Paid Memberships Pro WordPress plugin before version 2.9.12 is affected by CVE-2023-0631.
4
How does CVE-2023-0631 affect the software?
CVE-2023-0631 allows subscribers to render shortcodes that can concatenate attributes directly into an SQL query, potentially leading to SQL injection attacks.
5
Is there a fix available for CVE-2023-0631?
Yes, upgrading to version 2.9.12 of the Paid Memberships Pro WordPress plugin will fix CVE-2023-0631.