First published: Fri Jan 20 2023(Updated: )
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Strangerstudios Paid Memberships Pro | <2.9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23488 is an unauthenticated SQL injection vulnerability in the Paid Memberships Pro WordPress Plugin version < 2.9.8.
CVE-2023-23488 has a severity rating of 9.8 (critical).
CVE-2023-23488 affects the Paid Memberships Pro WordPress Plugin version < 2.9.8 and allows an attacker to execute SQL queries without authentication.
The CVE-2023-23488 exploit involves injecting malicious SQL code into the 'code' parameter of the '/pmpro/v1/order' REST route.
To fix CVE-2023-23488, update the Paid Memberships Pro WordPress Plugin to a version equal to or greater than 2.9.8.