WordPress Paid Memberships Pro 漏洞列表
共找到 4 个与 WordPress Paid Memberships Pro 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2021-25114: WordPress Paid Memberships Pro <2.6.7 - Blind SQL Injection POC
WordPress Paid Memberships Pro plugin before 2.6.7 is susceptible to blind SQL injection. The plugin does not escape the discount_code in one of its REST routes before using it in a SQL statement. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. -
CVE-2023-23488: WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection POC
WordPress Paid Memberships Pro plugin before 2.9.8 contains a blind SQL injection vulnerability in the 'code' parameter of the /pmpro/v1/order REST route. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. -
CVE-2021-25114: WordPress Paid Memberships Pro <2.6.7 - Blind SQL Injection POC
WordPress Paid Memberships Pro plugin before 2.6.7 is susceptible to blind SQL injection. The plugin does not escape the discount_code in one of its REST routes before using it in a SQL statement. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. -
CVE-2023-23488: WordPress Paid Memberships Pro <2.9.8 - Blind SQL Injection POC
WordPress Paid Memberships Pro plugin before 2.9.8 contains a blind SQL injection vulnerability in the 'code' parameter of the /pmpro/v1/order REST route. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.