Executive brief
WP eMember is a WordPress plugin used to manage memberships and restrict access to premium content. A critical security flaw allows unauthenticated attackers to perform SQL injection, which could lead to the theft of sensitive member data or unauthorized access to the site's database. This vulnerability is particularly dangerous as it can be exploited remotely without any login credentials.
Technical details
The WP eMember plugin for WordPress is vulnerable to an unauthenticated SQL injection due to improper neutralization of special elements used in an SQL command (CWE-89). An attacker can exploit this by sending specially crafted network requests to the affected site without requiring any prior authentication or user interaction. Successful exploitation allows the attacker to read sensitive information from the database, such as user credentials and membership details, and potentially impact the availability of the service. The vulnerability is addressed in version 10.9.4.
Affected products
- Tips and Tricks HQ WP eMember < v10.9.4
Timeline
- 2025-09-14: other: Reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
- 2026-06-16: disclosed: Vulnerability details published by Patchstack
- 2026-06-17: advisory: CVE published in NVD