Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hx6g-9577-37jq

Опубликовано: 08 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

EPSS

Процентиль: 99%
0.80944
Высокий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

EPSS

Процентиль: 99%
0.80944
Высокий

Дефекты

CWE-89