CVE-2021-25114: vulnerability in Paid Memberships Pro
Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection
Published · Updated
62Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 82%
from disclosure to weapon
Published on NVDFeb 7
VulnCheck+794d
exploitation probability
82%top 1% of all CVEs
observed exploitation
yesVulnCheck
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection
Affected products
Unknown · Paid Memberships ProRelated CVEs — Paid Memberships Pro
In the same product, most dangerous first.
CVE-2022-4830MEDIUMPaid Memberships Pro < 2.9.9 - Contributor+ Stored XSS via ShortcodeEPSS 65.0%CVE-2023-0631—Paid Memberships Pro < 2.9.12 - Subscriber+ SQL InjectionEPSS 60.5%CVE-2021-24979—Paid Memberships Pro < 2.6.6 - Reflected Cross-Site ScriptingEPSS 1.9%CVE-2024-1279MEDIUMPaid Memberships Pro < 2.12.9 - Contributor+ Arbitrary User Custom Field DisclosureEPSS 0.5%