{"api_version":"1","generated_at":"2026-07-24T23:36:04+00:00","cve":"CVE-2021-24728","urls":{"html":"https://cve.report/CVE-2021-24728","api":"https://cve.report/api/cve/CVE-2021-24728.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-24728","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-24728"},"summary":{"title":"CVE-2021-24728","description":"The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2021-09-13 18:15:00","updated_at":"2022-12-20 22:03:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29172","name":"https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29172","refsource":"MISC","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://wpscan.com/vulnerability/2277d335-1c90-4fa8-b0bf-25873c039c38","name":"https://wpscan.com/vulnerability/2277d335-1c90-4fa8-b0bf-25873c039c38","refsource":"MISC","tags":[],"title":"Attention Required! | Cloudflare","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://plugins.trac.wordpress.org/changeset/2566399/paid-member-subscriptions","name":"https://plugins.trac.wordpress.org/changeset/2566399/paid-member-subscriptions","refsource":"CONFIRM","tags":[],"title":"403 Forbidden","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-24728","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-24728","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Martin Vierula of Trustwave","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"24728","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cozmoslabs","cpe5":"membership_\\&_content_restriction_-_paid_member_subscriptions","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2021-24728","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC","TITLE":"Paid Member Subscriptions < 2.4.2 - Authenticated SQL Injection"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","generator":"WPScan CVE Generator","affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"Membership & Content Restriction – Paid Member Subscriptions","version":{"version_data":[{"version_affected":"<","version_name":"2.4.2","version_value":"2.4.2"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages."}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29172","name":"https://www.trustwave.com/en-us/resources/security-resources/security-advisories/?fid=29172"},{"refsource":"MISC","url":"https://wpscan.com/vulnerability/2277d335-1c90-4fa8-b0bf-25873c039c38","name":"https://wpscan.com/vulnerability/2277d335-1c90-4fa8-b0bf-25873c039c38"},{"refsource":"CONFIRM","url":"https://plugins.trac.wordpress.org/changeset/2566399/paid-member-subscriptions","name":"https://plugins.trac.wordpress.org/changeset/2566399/paid-member-subscriptions"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"CWE-89 SQL Injection","lang":"eng"}]}]},"credit":[{"lang":"eng","value":"Martin Vierula of Trustwave"}],"source":{"discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-09-13 18:15:00","lastModifiedDate":"2022-12-20 22:03:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cozmoslabs:membership_\\&_content_restriction_-_paid_member_subscriptions:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"2.4.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"24728","Ordinal":"199490","Title":"CVE-2021-24728","CVE":"CVE-2021-24728","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"24728","Ordinal":"1","NoteData":"The Membership & Content Restriction – Paid Member Subscriptions WordPress plugin before 2.4.2 did not sanitise, validate or escape its order and orderby parameters before using them in SQL statement, leading to Authenticated SQL Injections in the Members and Payments pages.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"24728","Ordinal":"2","NoteData":"2021-09-13","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"24728","Ordinal":"3","NoteData":"2021-09-13","Type":"Other","Title":"Modified"}]}}}