WordPress Plugin Vulnerabilities

Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi

Description

The plugin does not prevent users with at least the contributor role from leaking other users' sensitive information, including password hashes via an SQLi vector

Proof of Concept

Affects Plugins

References

Classification

Type
SQLI
OWASP top 10
CWE

Miscellaneous

Original Researcher
Scott Kingsley Clark
Submitter
Scott Kingsley Clark
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2024-07-09 (about 1 year ago)
Added
2024-07-09 (about 1 year ago)
Last Updated
2025-08-21 (about 4 months ago)

Other