CVE-2025-68060
7.6WPMart Team Member · Team Member
An SQL injection vulnerability in the WPMart Team Member plugin allows authenticated attackers with high privileges to execute blind SQL injection attacks.
Executive summary
An SQL injection vulnerability in the WPMart Team Member plugin allows high-privileged attackers to compromise database confidentiality and integrity, presenting a high risk to the hosting WordPress site.
Vulnerability
This flaw involves improper neutralization of special elements used in an SQL command, classified under CWE-89. The attack requires high privileges and network access without user interaction.
Business impact
A successful exploit could allow malicious actors to extract sensitive database contents, potentially leading to unauthorized data exposure or system disruption. Given the CVSS score of 7.6, this high-severity flaw threatens overall organizational data integrity and operational continuity.
Remediation
Immediate Action: Update the WordPress Team Member Plugin to version 8.6 or later as provided in the vendor solution.
Proactive Monitoring: Review database access controls and enable query logging to detect anomalous SQL execution patterns.
Compensating Controls: Implement a Web Application Firewall to filter malicious SQL injection payloads targeting database parameters.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Administrators must promptly apply the available plugin update to version 8.6 or higher to eliminate the underlying SQL injection risk. Maintaining rigorous update cycles for all third-party extensions remains essential for securing the application environment.
Sources
Originally found and disclosed by Jarno Vos (jrn5151) | Patchstack Bug Bounty Program, per the CVE Program record.