CVE-2023-0631: Strangerstudios Paid Memberships Pro
High severity, CVSS 8.8. EPSS: 60.5% chance of exploitation in the next 30 days.
The Paid Memberships Pro WordPress plugin before 2.9.12 does not prevent subscribers from rendering shortcodes that concatenate attributes directly into an SQL query.
Affected products
- Strangerstudios Paid Memberships Pro: before 2.9.12 (fixed in 2.9.12)
Published 2023-03-20. Last modified 2026-06-17.