Junglewise Threat Intelligence

CVE-2026-5073: ARMember Premium SQL injection in arm_directory_paging_action

CVE-2026-5073 · Severity: high · CVSS 7.5 · Published 2026-06-02

Technologies: ReputeInfo ARMember Premium. Vendors: ReputeInfo.

Executive brief

ARMember Premium, a popular WordPress plugin used for managing memberships and user directories, contains a security flaw that allows unauthorized individuals to access private database information. By sending a specially crafted request to the website's member directory search feature, an attacker can bypass security controls to steal sensitive data such as user details or site configurations. This could lead to a significant data breach and compromise the privacy of your registered members.

Technical details

A SQL injection vulnerability exists in the ARMember Premium plugin for WordPress due to insufficient input validation and lack of SQL preparation in the arm_get_directory_members() function. The vulnerability is exposed through the 'order' and 'orderby' parameters of the 'arm_directory_paging_action' AJAX action. Because these parameters are not properly escaped or handled via parameterized queries, an unauthenticated remote attacker can append malicious SQL commands to existing queries. This enables the extraction of sensitive data from the WordPress database. The issue affects all versions of the plugin up to and including 7.3.1.

Affected products

  • ReputeInfo ARMember Premium up to, and including, 7.3.1

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory

References