CVE-2021-25114

Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL Injection

Basic Information

CVE State
PUBLISHED
Reserved Date
January 14, 2021
Published Date
February 07, 2022
Last Updated
August 03, 2024
Vendor
Stranger Studios
Product
Paid Memberships Pro
Description
The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection
Tags
wordpress ios nuclei_scanner

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score

Score
73.55% (Percentile: 98.72%) as of 2025-05-26

Exploit Status

Exploited in the Wild
Yes (2025-04-28 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-04-28 00:00:00 UTC

Scanner Integrations

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Added to KEVIntel