S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-23488 Scanner

CVE-2023-23488 scanner - SQL Injection vulnerability in Paid Memberships Pro plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-23488
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Paid Memberships Pro WordPress Pluginby n/a
< 2.9.8
Updated Aug 22, 2026View on NVD →
Detail

The Paid Memberships Pro plugin for WordPress is one of the go-to plugins for creating membership websites. It provides the users with the ability to create membership levels, restrict content and sell products through the website. Additionally, users can customize the plugin as per their requirements. This plugin has been used by many websites to create membership plans for their users.

Recently, a vulnerability has been discovered in the Paid Memberships Pro plugin, identified as CVE-2023-23488. This vulnerability is an unauthenticated SQL injection vulnerability within the ‘code’ parameter of the ‘/pmpro/v1/order’ REST route. An attacker can exploit this vulnerability to inject malicious code into the website, leading to data breaches, website defacements, and even complete website takeovers.

Exploitation of this vulnerability can lead to severe consequences. The hacker can steal sensitive user information such as passwords, email addresses and other confidential data. Moreover, they can misuse the website to perform various cybercrimes such as infecting users' systems with malware, distributing spam or phishing attacks, and using the website as a proxy server to attack other websites or systems.

In conclusion, this vulnerability puts many websites at high risk of data breaches and website hacking. It is crucial to take the necessary precautions to prevent any such incidents from occurring. By using the pro features of s4e.io, website owners can stay informed about their digital assets' vulnerabilities and take the necessary actions to secure their online presence. Stay safe and stay informed!

 

REFERENCES

Solution Advice

To protect against this vulnerability, below are some precautions that can be taken:

  • Update the Paid Memberships Pro plugin to version 2.9.8 or higher as it contains a patch that addresses this vulnerability.
  • Install firewalls and intrusion detection systems to block suspicious activities.
  • Block potential SQL injection attempts using WAF (Web Application Firewall) rules.
  • Implement security solutions that detect and prevent attacks in real-time.
  • Regularly back up the website and scan for vulnerabilities. 

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-23488 scanner - SQL Injection vulnerability in Paid Memberships Pro plugin for Wordpress S4E