CVE Published: 20/01/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: tenable |
Vendor: n/a |
Product: Paid Memberships Pro WordPress Plugin Status : PUBLISHED
CVE-2023-23488 Description
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the \'code\' parameter of the \'/pmpro/v1/order\' REST route.