SQL Injection Vulnerability in Cozmo Labs Paid Member Subscriptions Plugin
CVE-2025-49870

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 July 2025

What is CVE-2025-49870?

A significant SQL injection vulnerability has been identified in the Cozmoslabs Paid Member Subscriptions plugin. This flaw allows attackers to manipulate SQL queries, potentially leading to unauthorized data access and database compromise. The issue affects all versions from the initial release up to version 2.15.1, making it crucial for users to update their systems and implement security measures to safeguard sensitive information.

Affected Version(s)

Paid Member Subscriptions <= 2.15.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ChuongVN (Patchstack Alliance)
.