← back
CVE-2021-25114observed exploitationCWE-89

Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection

62Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 82%
from disclosure to weapon
Published on NVDFeb 7
VulnCheck+794d
exploitation probability
82%top 1% of all CVEs
observed exploitation
yesVulnCheck
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection