• Alerts
  • Events
  • DCR
    • Explore Cyware Products
    Alerts Events DCR
    Go to listing page

    High-Risk SQLi Flaw Exposes WordPress Memberships Plugin Users

    • Malware and Vulnerabilities
    • September 01, 2025
    • infosecurity-magazine
    A critical unauthenticated SQL injection vulnerability has been discovered in the WordPress Paid Membership Subscriptions plugin, affecting versions up to 2.15.1. It allows unauthenticated attackers to inject malicious SQL queries into the database.
    Read More
    • WordPress
    • SQL injection
    • CVE-2025-49870
    • Paid Membership Subscriptions Plugin
    • Web Application Security
    Cyware Publisher

    Publisher

    Previous

    Spanish government cancels €10m contract using Huawei e ...

    Govt., Critical Infrastructure

    Next

    Crooks exploit Meta malvertising to target Android user ...

    Malware and Vulnerabilities


    RESOURCES
    Cyber Fusion Center Guide
    EVENTS

    News and Updates, Hacker News

    Get in touch with us now!

    1-855-692-9927


    Download Cyware Social App

    Terms of Use Privacy Policy © 2023