ZeroHour

CVE-2021-20678

CVSS 3.1
8.8 high
EPSS
2%p80
Published
()
Modified
Description

SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

Vendors
strangerstudios
Products
paid memberships pro
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.