Executive brief
The Supsystic Membership plugin for WordPress, which provides membership and community features for websites, contains a security flaw in its badges module. An unauthenticated attacker can exploit this vulnerability to run unauthorized database commands. This could lead to the theft of sensitive user information, site configuration data, or other private records stored in the website's database.
Technical details
An SQL injection vulnerability exists in the Supsystic Membership plugin for WordPress (version 1.4.7 and below) due to improper neutralization of user-supplied input in the 'search' and 'sidx' GET parameters. The flaw is located within the badges module's 'getTblList' route. An unauthenticated remote attacker can exploit this by sending specially crafted GET requests to the WordPress backend. Successful exploitation allows for time-based blind or UNION-based SQL injection, enabling the attacker to extract sensitive information from the database. The vulnerability was reportedly fixed following coordination with the WordPress Plugin Security team in December 2020.
Affected products
- Supsystic Membership by Supsystic <= 1.4.7
Timeline
- 2020-07-25: other: Vendor notified
- 2020-12-22: patched: Vulnerability fixed in plugin repository
- 2021-02-08: disclosed: Exploit-DB proof of concept published
- 2026-05-16: advisory: NVD/VulnCheck advisory published