cve/2023/CVE-2023-23488.md

36 lines
1.7 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-23488](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23488)
![](https://img.shields.io/static/v1?label=Product&message=Paid%20Memberships%20Pro%20WordPress%20Plugin&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Unauthenticated%20SQL%20Injection&color=brighgreen)
### Description
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.
### POC
#### Reference
- http://packetstormsecurity.com/files/171661/WordPress-Paid-Memberships-Pro-2.9.8-SQL-Injection.html
- https://www.tenable.com/security/research/tra-2023-2
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/Abdel-Faridh33/agms
- https://github.com/CVEDB/PoC-List
- https://github.com/CVEDB/awesome-cve-repo
- https://github.com/CVEDB/top
- https://github.com/JoshuaMart/JoshuaMart
- https://github.com/abrahim7112/Vulnerability-checking-program-for-Android
- https://github.com/cybfar/CVE-2023-23488-pmpro-2.8
- https://github.com/hktalent/TOP
- https://github.com/huyqa/Paid-Memberships-Pro-v2.9.8-WordPress-Plugin---Unauthenticated-SQL-Injection
- https://github.com/huyqa/Paid-Memberships-Pro-v2.9.8-WordPress-Plugin-Unauthenticated-SQL-Injection
- https://github.com/k0mi-tg/CVE-POC
- https://github.com/manas3c/CVE-POC
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/r3nt0n/CVE-2023-23488-PoC
2024-05-28 08:49:17 +00:00
- https://github.com/whoforget/CVE-POC
- https://github.com/youwizard/CVE-POC
2024-05-25 21:48:12 +02:00