The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 |
Status: PUBLISHED
Assigner: WPScan
Published: 2023-03-20T15:52:10.755Z
Updated: 2025-02-26T14:44:50.619Z
Reserved: 2023-02-01T22:57:30.482Z
Link: CVE-2023-0631
Updated: 2024-08-02T05:17:50.223Z
Status : Modified
Published: 2023-03-20T16:15:12.437
Modified: 2025-02-26T15:15:18.757
Link: CVE-2023-0631
No data.