KEVIntel
9.8
CVSS
Critical

CVE-2021-25114

PUBLISHED

Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection

Exploited in the wild Remote Low complexity No user interaction
Vendor
Unknown
Product
Paid Memberships Pro
Published
Feb 07, 2022
EPSS

Description

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

wordpress nuclei_scanner

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2025-04-28 00:00:00 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Apr 28, 2025

Scanner integrations

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Added to KEVIntel