CVE-2021-25114
07.02.2022, 16:15
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection
Vendor | Product | Version |
---|---|---|
strangerstudios | paid_memberships_pro | 2.4 ≤ 𝑥 < 2.4.5 |
strangerstudios | paid_memberships_pro | 2.5 ≤ 𝑥 < 2.5.11 |
strangerstudios | paid_memberships_pro | 2.6 ≤ 𝑥 < 2.6.7 |
𝑥
= Vulnerable software versions