Input validation vulnerability in Paid Memberships Pro – Restrict Member Access to Content, Courses, Communities – Free or Paid Subscriptions 2.9.7

The Paid Memberships Pro plugin for WordPress is a potential security risk if you have an older version (before 2.9.8). An unauthenticated attacker can use this plugin to get access to sensitive information from the database. This is done by adding extra SQL queries to the ‘code’ parameter in the /pmpro/v1/order REST route.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.