Impact
A remote attacker who can influence the Paid Member Subscriptions plugin’s processing of subscription requests can inject arbitrary SQL statements. This flaw permits the attacker to read, alter or delete subscription data stored in the WordPress database, thereby compromising data confidentiality, integrity and potentially enabling privilege escalation or further exploitation of the site.
Affected Systems
All WordPress installations running Cozmoslabs Paid Member Subscriptions plugins version 3.1.1 or older are vulnerable. The flaw exists in the plugin’s query handling logic and is present across all affected releases up to and including 3.1.1.
Risk and Exploitability
The CVSS score of 8.5 classifies this vulnerability as high severity, indicating significant impact if successful. The EPSS score is not available, but the vulnerability has not been listed in the CISA KEV catalog, suggesting it has not been widely exploited yet. Based on the nature of the flaw, the most likely attack vector is remote exploitation through the web interface of the plugin, although the exact prerequisites for successful injection are not detailed in the description.
OpenCVE Enrichment