CVE-2025-49870
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-49870 is a SQL Injection vulnerability in the Cozmoslabs Paid Member Subscriptions WordPress plugin, affecting all versions up to and including 2.15.1. The flaw was reported by researcher ChuongVN on May 30, 2025, and publicly disclosed on July 3–4, 2025. It carries a CVSS v3.1 base score of 7.5 (High), with a changed scope reflecting potential cross-boundary database impact (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is not properly sanitized before being incorporated into database queries. An unauthenticated remote attacker can craft malicious HTTP requests containing SQL metacharacters to manipulate the plugin's database queries, potentially extracting sensitive data. The attack requires high complexity but no authentication or user interaction, and the scope is changed — indicating the impact extends beyond the vulnerable component itself. The vulnerability was assigned Patchstack ID a1a90742ac79 and maps to CAPEC patterns including blind SQL injection (CAPEC-7) and command-line execution through SQL injection (CAPEC-108) (Patchstack).

Impact

Successful exploitation primarily threatens confidentiality, allowing an unauthenticated attacker to read sensitive data from the WordPress database — including member subscription records, user credentials (hashed passwords), email addresses, and payment-related metadata. Integrity impact is rated none, while availability impact is low. Given the plugin's role in managing paid memberships, data exposure could lead to account takeover, privacy violations, and regulatory consequences for site operators (Patchstack, Infosecurity Magazine).

Exploitability

No public proof-of-concept exploit code has been identified at this time, and there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.028% (0.000280), indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as a High priority vulnerability expected to be used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Paid Member Subscriptions plugin (versions ≤ 2.15.1) using tools like WPScan, Shodan, or Google dorks (e.g., inurl:/wp-content/plugins/paid-member-subscriptions).
  2. Identify vulnerable endpoint: Locate the plugin's front-end or back-end endpoints that accept user-controlled parameters passed to database queries without proper sanitization.
  3. Craft SQL injection payload: Construct a malicious HTTP request (GET or POST) containing SQL injection syntax (e.g., ' OR 1=1--, time-based blind payloads, or UNION-based payloads) targeting the vulnerable parameter.
  4. Extract database contents: Use automated tools such as sqlmap to enumerate the WordPress database, extracting tables such as wp_users, wp_pms_member_subscriptions, and other sensitive records.
  5. Leverage extracted data: Use harvested credentials or session tokens for account takeover, or use extracted member data for phishing or fraud (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests to Paid Member Subscriptions plugin endpoints containing SQL metacharacters (', --, UNION, SELECT, OR 1=1) in query parameters or POST body; high-frequency requests from a single IP to plugin-related URLs.
  • Logs: WordPress/Apache/Nginx access logs showing repeated requests with encoded SQL payloads (e.g., %27, %20UNION%20SELECT) to plugin endpoints; database error messages in wp-content/debug.log related to malformed SQL queries.
  • Database: Unexpected queries in MySQL slow query logs or general query logs involving UNION SELECT or time-delay functions (SLEEP(), BENCHMARK()) originating from the web application user.
  • File System: Presence of automated scanning tool artifacts (e.g., sqlmap output files) on attacker-controlled infrastructure; no direct file system changes expected from read-only SQL injection.

Mitigation and workarounds

The vendor Cozmoslabs has released version 2.15.2 of the Paid Member Subscriptions plugin, which patches this vulnerability. All site administrators running version 2.15.1 or earlier should update immediately via the WordPress plugin dashboard or by downloading the patched version from the WordPress plugin repository. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. If immediate updating is not possible, consider temporarily deactivating the plugin and consulting your hosting provider (Patchstack).

Community reactions

Patchstack, which discovered and coordinated disclosure of the vulnerability, highlighted it as high-priority and likely to be targeted in mass-exploit campaigns against WordPress sites (Patchstack). Wordfence included the vulnerability in its weekly WordPress vulnerability report for the week of June 30–July 6, 2025 (Wordfence). TechRadar and Infosecurity Magazine covered the issue, warning paid WordPress plugin users of the risk to member accounts and personal data (Infosecurity Magazine, TechRadar). CISA referenced the vulnerability in its weekly vulnerability bulletin (SB25-188) (CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-65640HIGH8.8
  • wordpress
NoYesAug 17, 2026
CVE-2026-11801HIGH7.5
  • wpadverts
NoYesAug 18, 2026
CVE-2026-13700MEDIUM5.9
  • wooms
NoNoAug 17, 2026
CVE-2026-14832MEDIUM5.3
  • shopsmart-loyalty-for-woocommerce
NoNoAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management