PT-2026-38353 · WordPress · Wpmart Team Member

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2025-68060

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions WPMart Team Member versions n/a through 8.5
Description Improper neutralization of special elements used in an SQL command allows for Blind SQL Injection. This occurs when the application fails to properly sanitize user-supplied data before including it in a database query, enabling an attacker to infer information from the database by observing the application's response to specific queries.
Recommendations Update WPMart Team Member to a version later than 8.5.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-68060

Affected Products

Wpmart Team Member