Paid WordPress users are wary – the concern of the security flaw puts accounts and information at risk


  • An inappropriate neutralization defect was found in the WordPress paid membership subscription plugin
  • This plugin is used by more than 10,000 sites, allowing subscriptions and paying user accounts
  • A fix is ​​now available, so users must update immediately

A high severity vulnerability has been discovered in a popular WordPress premium plugin, allowing threat actors to access or exfiltrate sensitive data without authentication.

The CHUONGVN security researcher of the Patchstack Alliance recently found an “incorrect neutralization of the special elements used in an SQL control defect”, affecting the membership subscription plugin paid by WordPress.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top