CVE-2023-23488

Publication date

2023-01-20 00:00:00

Family

tenable

State

PUBLISHED

Description

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the code parameter of the /pmpro/v1/order REST route.