PT-2026-38353 · WordPress · Wpmart Team Member
Published
2026-05-07
·
Updated
2026-05-07
·
CVE-2025-68060
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
WPMart Team Member versions n/a through 8.5
Description
Improper neutralization of special elements used in an SQL command allows for Blind SQL Injection. This occurs when the application fails to properly sanitize user-supplied data before including it in a database query, enabling an attacker to infer information from the database by observing the application's response to specific queries.
Recommendations
Update WPMart Team Member to a version later than 8.5.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpmart Team Member