
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49870 is a SQL Injection vulnerability in the Cozmoslabs Paid Member Subscriptions WordPress plugin, affecting all versions up to and including 2.15.1. The flaw was reported by researcher ChuongVN on May 30, 2025, and publicly disclosed on July 3–4, 2025. It carries a CVSS v3.1 base score of 7.5 (High), with a changed scope reflecting potential cross-boundary database impact (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), meaning user-supplied input is not properly sanitized before being incorporated into database queries. An unauthenticated remote attacker can craft malicious HTTP requests containing SQL metacharacters to manipulate the plugin's database queries, potentially extracting sensitive data. The attack requires high complexity but no authentication or user interaction, and the scope is changed — indicating the impact extends beyond the vulnerable component itself. The vulnerability was assigned Patchstack ID a1a90742ac79 and maps to CAPEC patterns including blind SQL injection (CAPEC-7) and command-line execution through SQL injection (CAPEC-108) (Patchstack).
Successful exploitation primarily threatens confidentiality, allowing an unauthenticated attacker to read sensitive data from the WordPress database — including member subscription records, user credentials (hashed passwords), email addresses, and payment-related metadata. Integrity impact is rated none, while availability impact is low. Given the plugin's role in managing paid memberships, data exposure could lead to account takeover, privacy violations, and regulatory consequences for site operators (Patchstack, Infosecurity Magazine).
No public proof-of-concept exploit code has been identified at this time, and there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.028% (0.000280), indicating a currently low probability of exploitation in the near term. However, Patchstack classifies this as a High priority vulnerability expected to be used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).
inurl:/wp-content/plugins/paid-member-subscriptions).' OR 1=1--, time-based blind payloads, or UNION-based payloads) targeting the vulnerable parameter.sqlmap to enumerate the WordPress database, extracting tables such as wp_users, wp_pms_member_subscriptions, and other sensitive records.', --, UNION, SELECT, OR 1=1) in query parameters or POST body; high-frequency requests from a single IP to plugin-related URLs.%27, %20UNION%20SELECT) to plugin endpoints; database error messages in wp-content/debug.log related to malformed SQL queries.UNION SELECT or time-delay functions (SLEEP(), BENCHMARK()) originating from the web application user.sqlmap output files) on attacker-controlled infrastructure; no direct file system changes expected from read-only SQL injection.The vendor Cozmoslabs has released version 2.15.2 of the Paid Member Subscriptions plugin, which patches this vulnerability. All site administrators running version 2.15.1 or earlier should update immediately via the WordPress plugin dashboard or by downloading the patched version from the WordPress plugin repository. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. If immediate updating is not possible, consider temporarily deactivating the plugin and consulting your hosting provider (Patchstack).
Patchstack, which discovered and coordinated disclosure of the vulnerability, highlighted it as high-priority and likely to be targeted in mass-exploit campaigns against WordPress sites (Patchstack). Wordfence included the vulnerability in its weekly WordPress vulnerability report for the week of June 30–July 6, 2025 (Wordfence). TechRadar and Infosecurity Magazine covered the issue, warning paid WordPress plugin users of the risk to member accounts and personal data (Infosecurity Magazine, TechRadar). CISA referenced the vulnerability in its weekly vulnerability bulletin (SB25-188) (CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."