CVE-2023-23488 is a critical unauthenticated SQL injection vulnerability affecting the Paid Memberships Pro WordPress Plugin versions prior to 2.9.8. This flaw allows remote attackers to execute arbitrary SQL queries through the 'code' parameter of the '/pmpro/v1/order' REST route. With a CVSS score of 9.8, it poses a severe risk, enabling full compromise of confidentiality, integrity, and availability without user interaction. Exploit code is publicly available, including Metasploit modules and Nuclei templates, and it has garnered significant community attention with 11 mentions and media coverage, indicating a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.9.8CPE matchmatch criteria | cpe:2.3:a:strangerstudios:paid_memberships_pro:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
SQL Injection in Multiple WordPress Plugins
Jan 12, 2023SQL Injection in Multiple WordPress Plugins
Jan 12, 2023SQL Injection in Multiple WordPress Plugins
Jan 12, 2023SQL Injection in Multiple WordPress Plugins
Jan 12, 2023