SQL Injection Vulnerability in WP-Members Membership Plugin for WordPress
CVE-2026-2363
6.5MEDIUM
What is CVE-2026-2363?
The WP-Members Membership Plugin for WordPress is susceptible to SQL injection through the 'order_by' attribute present in the [wpmem_user_membership_posts] shortcode. This vulnerability arises from inadequate input sanitization on user-supplied parameters and the absence of rigorous preparation of SQL queries. As a result, authenticated users with Contributor-level access or higher can inject additional SQL queries, potentially retrieving sensitive data from the database.
Affected Version(s)
WP-Members Membership Plugin 0 <= 3.5.5.1