
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
The Paid Memberships Pro WordPress plugin versions before 2.6.7 contained an unauthenticated SQL injection vulnerability (CVE-2021-25114). The vulnerability existed because the plugin failed to properly escape the discount_code parameter in one of its REST routes, which was accessible to unauthenticated users (WPScan).
The vulnerability was discovered in the REST API endpoint that handles checkout levels. The issue specifically involved the discountcode parameter in the /pmpro/v1/checkoutlevel route, which was not properly escaped before being used in SQL queries. The vulnerability received a CVSS score of 10.0 (Critical), indicating the highest severity level. It was classified as a SQL Injection (SQLI) vulnerability falling under the OWASP Top 10 category A1: Injection and CWE-89 (WPScan).
The vulnerability could be exploited to perform distributed denial of service (DDoS) attacks and potentially allow attackers to access sensitive information from the WordPress database that was not intended to be public (PMPro Blog).
The vulnerability was patched in version 2.6.7 of the Paid Memberships Pro plugin. The fix involved updating the escaping in the pmprogetLevelAtCheckout and pmprocheckDiscountCode functions by wrapping the $discountcode and $levelid variables with the esc_sql function. Users were advised to update to version 2.6.7 as soon as possible (PMPro Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”