Sceawere

Vulnerability Detail

CVE-2026-105317UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Subscriber SQL Injection in Paid Member Subscriptions

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
16h ago
Vendor
Cozmoslabs
Product
Paid Member Subscriptions
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-10-06T09:17:41.043Z",
  "pubdate": "2026-10-06T09:17:41.043Z",
  "executiveSummary": "Paid Member Subscriptions versions 3.1.1 and below are susceptible to a SQL Injection vulnerability. This security flaw allows an authenticated user with Subscriber-level privileges to execute arbitrary SQL commands against the underlying application database.\nThe vulnerability arises due to improper neutralization of user-supplied data before incorporating it into database queries. By manipulating input parameters, an attacker can bypass access controls, retrieve sensitive information, or modify database records.\nThe impact is significant, potentially leading to unauthorized data exfiltration, including user credentials, payment details, or proprietary content stored within the database. Furthermore, depending on the database configuration, it may be possible to escalate privileges or gain remote code execution capabilities through database-specific functions.\nThis vulnerability requires a valid Subscriber account to exploit, as the injection point is accessible within the subscriber-authenticated context. The risk is classified as critical, necessitating immediate attention to prevent unauthorized data access and potential site compromise.",
  "technicalDetails": "The vulnerability exists due to insufficient sanitization and parameterized query implementation within the Paid Member Subscriptions plugin's handling of user-submitted data. Specifically, the application fails to adequately validate or escape inputs provided by subscribers, allowing for the injection of malicious SQL syntax into queries executed by the plugin.\nThe attack flow commences with the attacker authenticated as a subscriber. The attacker identifies input fields or parameters that are processed by the vulnerable plugin components without proper prepared statements. By crafting a payload, the attacker can manipulate the structure of the database query. For example, by inserting single quotes and SQL operators such as UNION, SELECT, or OR, the attacker can force the database to execute unintended operations.\nThe injection occurs because the application concatenates user input directly into SQL strings. When the database engine processes these strings, it fails to distinguish between data and command instructions. This lack of clear separation allows for 'In-Band' SQL injection where the result of the injected query is reflected in the application response, or 'Blind' SQL injection where the attacker infers data based on true/false conditions of the application response.\nBecause the vulnerability is triggered by a subscriber-level user, the exploit is restricted to the authenticated environment; however, given that many WordPress sites allow public subscriber registration, the barrier to entry is minimal. Once the SQL injection vector is validated, an attacker can perform enumeration of table names, column structures, and sensitive system variables. If the database user associated with the WordPress installation possesses high-level privileges, the attacker could theoretically perform administrative actions, drop tables, or potentially leverage database-specific features like 'INTO OUTFILE' to write files to the web server's filesystem, leading to full compromise.\nThe root cause is a failure to adhere to the WordPress security best practices regarding database interaction, specifically the omission of the $wpdb->prepare() function or equivalent parameterized querying mechanisms for dynamic SQL operations. This allows the malicious input to escape the intended query boundary, granting the attacker control over the logical flow of the SQL execution."
}
CVE-2026-105317: Subscriber SQL Injection in Paid Member Subscriptions (HIGH Severity, CVSS: 8.5) | Sceawere