
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2363 is a SQL Injection vulnerability in the WP-Members Membership Plugin for WordPress, affecting all versions up to and including 3.5.5.1. The flaw exists in the order_by attribute of the [wpmem_user_membership_posts] shortcode, where insufficient escaping of user-supplied input allows authenticated attackers to append malicious SQL queries. It was published on March 4, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), arising from insufficient escaping of the order_by shortcode attribute and inadequate preparation of the underlying SQL query in class-wp-members-products.php (lines 490 and 496 in version 3.5.5.1). An authenticated attacker with at minimum Contributor-level access can craft a malicious shortcode invocation that appends additional SQL statements to the existing query, enabling blind or union-based data extraction from the WordPress database. The attack is network-based, requires low privileges, and no user interaction (Wordfence, WP-Members Source).
Successful exploitation allows an authenticated attacker to extract sensitive information from the WordPress database, including user credentials, email addresses, membership data, and other confidential records stored in the database. The impact is limited to confidentiality — integrity and availability are not directly affected by this vulnerability. In a multi-site or high-value WordPress environment, database exposure could facilitate account takeover or further lateral movement (Wordfence, Red Hat CVE).
The vulnerability requires Contributor-level authentication, which limits opportunistic exploitation but remains accessible to any registered user on sites that allow contributor registration. The EPSS score is approximately 0.026% (0.000260), indicating a low current probability of active exploitation. No public proof-of-concept exploit code, exploit kit integration, threat actor attribution, or CISA KEV catalog listing has been identified for this CVE at this time (Feedly).
[wpmem_user_membership_posts] shortcode on accessible pages.order_by attribute, e.g., [wpmem_user_membership_posts order_by="id DESC UNION SELECT ...--"], injecting additional SQL clauses.[wpmem_user_membership_posts] shortcode with unusual or encoded order_by parameter values; database error messages in WordPress debug logs referencing unexpected SQL syntax.UNION SELECT, INFORMATION_SCHEMA, or stacked queries originating from WordPress shortcode processing.[wpmem_user_membership_posts] shortcode, such as database table names, user hashes, or other non-membership data appearing in page content.The vulnerability was addressed in a patch committed to the WP-Members plugin trunk (changeset 3468716), which adds proper escaping and SQL query preparation for the order_by shortcode attribute. Site administrators should update the WP-Members Membership Plugin to a version beyond 3.5.5.1 as soon as a patched release is available. As an interim workaround, restrict Contributor-level registration on the site or disable use of the [wpmem_user_membership_posts] shortcode until the plugin is updated (WP-Members Patch, Wordfence).
The vulnerability was discovered and reported through Wordfence, which published the threat intelligence entry. No significant public researcher commentary, vendor statements beyond the patch, or notable media coverage has been identified for this CVE at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."