SQL Injection Vulnerability in User Registration & Membership Plugin for WordPress
CVE-2025-9085

4.9MEDIUM

What is CVE-2025-9085?

The User Registration & Membership plugin for WordPress has a vulnerability that allows authenticated users with administrator-level access to exploit SQL injection through the 's' parameter. Due to inadequate escaping of user-supplied data and insufficient preparation of the SQL query, attackers can manipulate existing queries to execute unauthorized commands. This could lead to the exposure of sensitive database information, posing a serious threat to WordPress sites utilizing this plugin version 4.3.0.

Affected Version(s)

User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin * <= 4.3.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jack Pas
.
CVE-2025-9085 : SQL Injection Vulnerability in User Registration & Membership Plugin for WordPress