Vulnerability record · CVE-2023-23488 · published 20 January 2023
CVE-2023-23488: Paid Memberships Pro WordPress plugin unauthenticated SQL injection
Strangerstudios · Paid Memberships Pro
The Paid Memberships Pro WordPress plugin before version 2.9.8 is affected by an unauthenticated SQL injection in the 'code' parameter of the '/pmpro/v1/order' REST route. Because the endpoint is reachable without credentials and the flaw is a SQL injection, it exposes the site's database to direct manipulation.
Description
The Paid Memberships Pro WordPress Plugin, version < 2.9.8, is affected by an unauthenticated SQL injection vulnerability in the 'code' parameter of the '/pmpro/v1/order' REST route.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and full confidentiality, integrity and availability impact, combined with a very high EPSS score.
What it is
The Paid Memberships Pro WordPress plugin before version 2.9.8 is affected by an unauthenticated SQL injection in the 'code' parameter of the '/pmpro/v1/order' REST route. Because the endpoint is reachable without credentials and the flaw is a SQL injection, it exposes the site's database to direct manipulation.
Impact
An attacker can read and modify database contents, including membership and user data, and potentially escalate to broader site compromise depending on database privileges.
Attack surface
Reached over the network via the WordPress REST API route '/pmpro/v1/order' with a crafted 'code' parameter. No authentication or user interaction is required per the CVSS vector (PR:N, UI:N).
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.9246, 99.82nd percentile), indicating substantial predicted exploitation activity. Reference tags are limited to a third-party advisory and a Packet Storm posting, with no explicit exploit-availability tag.
What to do
- Update Paid Memberships Pro to version 2.9.8 or later immediately.
- If patching cannot be done at once, block or restrict access to the '/pmpro/v1/order' REST route at the web server or WAF.
- Audit database and membership records for unexpected changes or injected content.
- Rotate database credentials and review database user privileges to limit blast radius.
- Monitor WordPress plugin update status to confirm the fixed version is deployed across all sites.
Detection
- Inspect web server and WAF logs for requests to '/pmpro/v1/order' with suspicious or SQL-like values in the 'code' parameter.
- Alert on SQL error strings or unusual query patterns in application and database logs tied to that route.
- Monitor for anomalous database reads or writes originating from the WordPress application account.
- Review REST API access logs for unauthenticated calls to Paid Memberships Pro endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-23488 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-23488), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.