CVE-2025-68060

7.6

WPMart Team Member · Team Member

An SQL injection vulnerability in the WPMart Team Member plugin allows authenticated attackers with high privileges to execute blind SQL injection attacks.

Executive summary

An SQL injection vulnerability in the WPMart Team Member plugin allows high-privileged attackers to compromise database confidentiality and integrity, presenting a high risk to the hosting WordPress site.

Vulnerability

This flaw involves improper neutralization of special elements used in an SQL command, classified under CWE-89. The attack requires high privileges and network access without user interaction.

Business impact

A successful exploit could allow malicious actors to extract sensitive database contents, potentially leading to unauthorized data exposure or system disruption. Given the CVSS score of 7.6, this high-severity flaw threatens overall organizational data integrity and operational continuity.

Remediation

Immediate Action: Update the WordPress Team Member Plugin to version 8.6 or later as provided in the vendor solution.

Proactive Monitoring: Review database access controls and enable query logging to detect anomalous SQL execution patterns.

Compensating Controls: Implement a Web Application Firewall to filter malicious SQL injection payloads targeting database parameters.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Administrators must promptly apply the available plugin update to version 8.6 or higher to eliminate the underlying SQL injection risk. Maintaining rigorous update cycles for all third-party extensions remains essential for securing the application environment.

Sources

Originally found and disclosed by Jarno Vos (jrn5151) | Patchstack Bug Bounty Program, per the CVE Program record.