The Paid Memberships Pro plugin for WordPress is a potential security risk if you have an older version (before 2.9.8). An unauthenticated attacker can use this plugin to get access to sensitive information from the database. This is done by adding extra SQL queries to the ‘code’ parameter in the /pmpro/v1/order REST route.