WordPress users paid are careful: the worrying security defect puts accounts and information at risk


  • An inadequate neutralization failure was found in the complement of WordPress paid membership subscriptions
  • This complement is used by more than 10,000 sites, enabling memberships and paying user accounts
  • Now there is an available patch, so users must be updated immediately

High severity vulnerability has been discovered in a popular premium WordPress complement, allowing threat actors to access or exfilt confidential data without authentication.

Chuongvn’s security researcher at Patchstack Alliance recently found “inappropriate neutralization of special elements used in a SQL command”, which affects the complement of word -paid membership subscriptions of WordPress.

Leave a Comment

Your email address will not be published. Required fields are marked *