Security Advisory

CVE-2023-23488

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-01-20 00:00:00
Last updated 2025-04-03 20:05:09
Assigner tenable
State PUBLISHED

Description

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the code parameter of the /pmpro/v1/order REST route.