HTTP: WordPress Plugin pmpro_shortcode_membership SQL Injection

This signature detects attempts to exploit a known vulnerability against WordPress. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.

Affected Products

Strangerstudios paid_memberships_pro

Short Name
HTTP:SQL:INJ:WORDPRESS-PMPRO
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2023-0631 Injection Plugin SQL WordPress pmpro_shortcode_membership
Release Date
09/19/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3693
False Positive
Unknown
Vendors

Strangerstudios

Found a potential security threat?