Vulnerability CVE-2021-24728


Published: 2021-09-13

Description:
The Membership & Content Restriction ?? Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://plugins.trac.wordpress.org/changeset/2566399/paid-member-subscriptions
https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29172
https://wpscan.com/vulnerability/2277d335-1c90-4fa8-b0bf-25873c039c38

Copyright 2024, cxsecurity.com

 

Back to Top