Junglewise Threat Intelligence

CVE-2026-1865: WPEverest User Registration & Membership SQL injection in membership_ids

CVE-2026-1865 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: WPEverest User Registration. Vendors: WPEverest.

Executive brief

A popular WordPress plugin used for managing user registrations and paid memberships is vulnerable to a security flaw that could allow logged-in users to access sensitive database information. By exploiting this weakness, an attacker with even a basic subscriber account could run unauthorized database commands. This could lead to the exposure of private user data or internal site configuration details, potentially compromising the privacy of your members.

Technical details

The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping and lack of preparation on the 'membership_ids[]' parameter within SQL queries. This vulnerability exists in all versions up to and including 5.1.2. An authenticated attacker with Subscriber-level permissions or higher can exploit this by sending crafted requests to append malicious SQL commands to existing queries. Successful exploitation allows the attacker to extract sensitive information from the site's database. A patch has been identified in changeset 3469042.

Affected products

  • WPEverest User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Up to, and including, 5.1.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References

Related threats