cleantalk

Vulnerabilities and Security Researches

Security report for CVE Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions > CVE-2023-0631

CVE, Research URL

CVE-2023-0631

Published on
Mar 20, 2023
Research Description
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
Affected versions
Min -, max 2.9.12.
Status
vulnerable