Impact
Sup Supsystic Membership 1.4.7 contains an SQL injection flaw that allows attackers to send crafted GET requests with malicious payloads in the ‘search’ and ‘sidx’ parameters of the badges module. By exploiting time‑based blind or UNION‑based techniques, an adversary can execute arbitrary SQL statements against the WordPress database, enabling extraction of sensitive data or modification of the database content.
Affected Systems
The vulnerability affects WordPress sites that have the Sup Supsystic Membership plugin, version 1.4.7, installed. Sites running this plugin without an updated version are susceptible.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability with significant impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but its web‑based, unauthenticated nature and lack of authentication requirements make it highly exploitable on exposed WordPress sites. Attackers can target the plugin’s public endpoint, leveraging the injection to extract or alter database contents.
OpenCVE Enrichment