ZeroHour

CVE-2023-0631

PoC
CVSS 3.1
8.8 high
EPSS
60%p99
Published
()
Modified
Description

The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.

Vendors
strangerstudios
Products
paid memberships pro
Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.