First published: Tue Jul 09 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 3.0.5.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paid Memberships Pro | <3.0.6 |
Update to 3.0.6 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37486 is considered a high-severity vulnerability due to its potential for SQL injection exploitation.
To fix CVE-2024-37486, upgrade Paid Memberships Pro to version 3.0.6 or later.
CVE-2024-37486 affects Paid Memberships Pro versions prior to 3.0.6.
CVE-2024-37486 is classified as an SQL injection vulnerability due to improper neutralization of special elements in SQL commands.
Yes, CVE-2024-37486 can be exploited remotely if attacker has access to the vulnerable component.