CVE-2021-25114

Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection

Basic Information

CVE State
PUBLISHED
Reserved Date
January 14, 2021
Published Date
February 07, 2022
Last Updated
August 03, 2024
Vendor
Unknown
Product
Paid Memberships Pro
Description
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

CVSS Scores

EPSS Score

Score
73.55% (Percentile: 98.71%) as of 2025-04-29

Exploit Status

Exploited in the Wild
Yes (added 2025-04-28 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-04-28 00:00:00 UTC

Scanner Integrations