S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-25114 Scanner

CVE-2021-25114 scanner - SQL Injection vulnerability in Paid Memberships Pro plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-25114
9.8
CVSS

The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Paid Memberships Pro
AFFECTED< 2.6.7SAFE ✓≥ 2.6.7
Updated Aug 21, 2026View on NVD →
Detail

Paid Memberships Pro is a popular WordPress plugin used for managing membership sites. It provides various features like creating and managing membership levels, handling payments, and restricting access to content. With over 100,000 active installations, this plugin is widely used by many companies and organizations to provide their users with exclusive content and services.

Recently, a vulnerability was detected in the Paid Memberships Pro plugin, known as CVE-2021-25114. This vulnerability is related to the plugin's REST route, which is accessible to unauthenticated users. The plugin does not properly escape the discount code parameter before using it in a SQL statement, which leads to SQL injection. This vulnerability allows attackers to inject malicious SQL queries into the database, which can compromise the security of the application and sensitive user data.

Exploiting this vulnerability can lead to severe consequences for a website. Attackers can steal sensitive user information like usernames, emails, and passwords stored in the database. They can also alter or delete data, damage the website's functionality, or even take full control of the website. As a result, users' trust in the company or organization can be severely impacted, leading to a loss of business and reputation.

In conclusion, the Paid Memberships Pro plugin vulnerability CVE-2021-25114 is a severe security risk for websites using this plugin. To ensure the safety and security of their digital assets, website administrators must take necessary precautions and implement proper security measures. With the pro features of s4e.io, users can easily and quickly learn about vulnerabilities in their digital assets, including the Paid Memberships Pro plugin. Being aware of such vulnerabilities can help users take necessary steps to protect their website and prevent potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website administrators can take the following precautions:

  • Update the Paid Memberships Pro plugin to the latest version, which includes the fix for this vulnerability.
  • Use plugins or security solutions that can detect and prevent SQL injection attacks.
  • Implement proper input validation and sanitization techniques for all user-generated data.
  • Avoid exposing the REST API to unauthenticated users if possible.
  • Regularly monitor website logs and security alerts for any suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.