Description
Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
Published: 2026-10-06
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Remote database manipulation and potential unauthorized data modification or disclosure
Action: Immediate Patch
AI Analysis

Impact

A remote attacker who can influence the Paid Member Subscriptions plugin’s processing of subscription requests can inject arbitrary SQL statements. This flaw permits the attacker to read, alter or delete subscription data stored in the WordPress database, thereby compromising data confidentiality, integrity and potentially enabling privilege escalation or further exploitation of the site.

Affected Systems

All WordPress installations running Cozmoslabs Paid Member Subscriptions plugins version 3.1.1 or older are vulnerable. The flaw exists in the plugin’s query handling logic and is present across all affected releases up to and including 3.1.1.

Risk and Exploitability

The CVSS score of 8.5 classifies this vulnerability as high severity, indicating significant impact if successful. The EPSS score is not available, but the vulnerability has not been listed in the CISA KEV catalog, suggesting it has not been widely exploited yet. Based on the nature of the flaw, the most likely attack vector is remote exploitation through the web interface of the plugin, although the exact prerequisites for successful injection are not detailed in the description.

Generated by OpenCVE AI on October 6, 2026 at 10:58 UTC.

Remediation

Vendor Solution

Update the WordPress Paid Member Subscriptions plugin to the latest available version (at least 3.1.2).


OpenCVE Recommended Actions

  • Update the Paid Member Subscriptions plugin to version 3.1.2 or later.
  • If an update is not immediately available, disable or remove the plugin from the site until the patch is applied.
  • Limit the database user privileges used by WordPress to the minimum required for normal operation to reduce the impact of any successful injection.

Generated by OpenCVE AI on October 6, 2026 at 10:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
Title WordPress Paid Member Subscriptions plugin <= 3.1.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T10:31:25.873Z

Reserved: 2026-10-05T07:36:24.213Z

Link: CVE-2026-105317

cve-icon Vulnrichment

Updated: 2026-10-06T10:27:54.946Z

cve-icon NVD

Status : Received

Published: 2026-10-06T09:17:41.043

Modified: 2026-10-06T11:17:16.633

Link: CVE-2026-105317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T11:00:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')