Vulnerabilities > Strangerstudios > Paid Memberships PRO > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-11-01 | CVE-2024-37277 | Unspecified vulnerability in Strangerstudios Paid Memberships PRO Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4. | 9.8 |
2023-01-20 | CVE-2023-23488 | SQL Injection vulnerability in Strangerstudios Paid Memberships PRO The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route. | 9.8 |
2022-02-07 | CVE-2021-25114 | SQL Injection vulnerability in Strangerstudios Paid Memberships PRO The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection | 9.8 |