The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2023-03-20 09:15
Updated : 2023-03-21 04:51
NVD link : CVE-2023-0631
Mitre link : CVE-2023-0631
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
No product.