The Paid Memberships Pro plugin for WordPress is not secure in versions up to and including 2.9.11. This means that someone with a certain level of access can use it to get sensitive information from the database. They can do this by adding extra code to the ‘membership’ shortcode