CVE-2026-2363: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2363 is a SQL Injection vulnerability in the WP-Members Membership Plugin for WordPress, affecting all versions up to and including 3.5.5.1. The flaw exists in the order_by attribute of the [wpmem_user_membership_posts] shortcode, where insufficient escaping of user-supplied input allows authenticated attackers to append malicious SQL queries. It was published on March 4, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from insufficient escaping of the order_by shortcode attribute and inadequate preparation of the underlying SQL query in class-wp-members-products.php (lines 490 and 496 in version 3.5.5.1). An authenticated attacker with at minimum Contributor-level access can craft a malicious shortcode invocation that appends additional SQL statements to the existing query, enabling blind or union-based data extraction from the WordPress database. The attack is network-based, requires low privileges, and no user interaction (Wordfence, WP-Members Source).

Impact

Successful exploitation allows an authenticated attacker to extract sensitive information from the WordPress database, including user credentials, email addresses, membership data, and other confidential records stored in the database. The impact is limited to confidentiality — integrity and availability are not directly affected by this vulnerability. In a multi-site or high-value WordPress environment, database exposure could facilitate account takeover or further lateral movement (Wordfence, Red Hat CVE).

Exploitability

The vulnerability requires Contributor-level authentication, which limits opportunistic exploitation but remains accessible to any registered user on sites that allow contributor registration. The EPSS score is approximately 0.026% (0.000260), indicating a low current probability of active exploitation. No public proof-of-concept exploit code, exploit kit integration, threat actor attribution, or CISA KEV catalog listing has been identified for this CVE at this time (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running WP-Members Membership Plugin version ≤ 3.5.5.1 that use the [wpmem_user_membership_posts] shortcode on accessible pages.
  2. Obtain Contributor Access: Register or compromise an account with at least Contributor-level privileges on the target WordPress site.
  3. Craft Malicious Shortcode: Create or edit a post/page containing the shortcode with a manipulated order_by attribute, e.g., [wpmem_user_membership_posts order_by="id DESC UNION SELECT ...--"], injecting additional SQL clauses.
  4. Trigger Execution: Publish or preview the post to cause the server to execute the injected SQL query against the WordPress database.
  5. Extract Data: Retrieve the query results from the rendered page output or via error messages, extracting sensitive database contents such as user hashes, emails, or membership records (Wordfence, WP-Members Source).

Indicators of compromise

  • Logs: WordPress/web server access logs showing POST or GET requests to pages containing [wpmem_user_membership_posts] shortcode with unusual or encoded order_by parameter values; database error messages in WordPress debug logs referencing unexpected SQL syntax.
  • Database: Unexpected or anomalous queries in MySQL/MariaDB slow query logs or general query logs involving UNION SELECT, INFORMATION_SCHEMA, or stacked queries originating from WordPress shortcode processing.
  • Application: Unusual output on pages rendering the [wpmem_user_membership_posts] shortcode, such as database table names, user hashes, or other non-membership data appearing in page content.

Mitigation and workarounds

The vulnerability was addressed in a patch committed to the WP-Members plugin trunk (changeset 3468716), which adds proper escaping and SQL query preparation for the order_by shortcode attribute. Site administrators should update the WP-Members Membership Plugin to a version beyond 3.5.5.1 as soon as a patched release is available. As an interim workaround, restrict Contributor-level registration on the site or disable use of the [wpmem_user_membership_posts] shortcode until the plugin is updated (WP-Members Patch, Wordfence).

Community reactions

The vulnerability was discovered and reported through Wordfence, which published the threat intelligence entry. No significant public researcher commentary, vendor statements beyond the patch, or notable media coverage has been identified for this CVE at this time.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management