PT-2026-45845 · WordPress · Armember Premium
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ARMember Premium versions prior to 7.3.2
Description
An SQL Injection issue exists in the ARMember Premium plugin for WordPress. The
get private content data AJAX action fails to properly sanitize the sSortDir 0 parameter, which is concatenated directly into the ORDER BY clause of an SQL query without a whitelist check. This allows authenticated attackers with Subscriber-level access or higher to append additional SQL queries to extract sensitive information from the database. This issue is only exploitable if the User Private Content addon is enabled.Recommendations
Update to a version newer than 7.3.1.
As a temporary mitigation, disable the User Private Content addon.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Armember Premium