Executive brief
WP eMember is a WordPress plugin used to manage memberships and protect premium content. A security flaw in versions up to 10.2.2 allows unauthorized individuals to access sensitive system information that should be restricted. This exposure could potentially reveal configuration details or other internal data that helps an attacker plan further strikes against the website.
Technical details
The WP eMember plugin for WordPress (v10.2.2 and below) is vulnerable to CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere. This vulnerability allows a remote, unauthenticated attacker to retrieve embedded sensitive data from the system via the web interface. The attack vector is network-based with low complexity and requires no user interaction. While the specific nature of the 'embedded' data is not detailed in the advisory, it is classified as sensitive system information that could facilitate further exploitation. As of the advisory date, no official patch has been released.
Affected products
- Tips and Tricks HQ WP eMember n/a through 10.2.2
Timeline
- 2025-09-12: other: Reported by Tran Nguyen Bao Khanh
- 2026-06-04: advisory: Published by Patchstack and NVD