S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 13, 2026

CVE-2025-2221 Scanner

CVE-2025-2221 Scanner - SQL Injection vulnerability in WordPress WPCOM Member

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-2221
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in all versions up to, and including, 1.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WPCOM Memberby whyun
0
Updated Aug 22, 2026View on NVD →
Detail

WordPress is a widely used content management system (CMS) that powers millions of websites worldwide. Plugins like WPCOM Member extend its functionality by providing additional features for membership sites. Many small to medium businesses and independent website developers use such plugins to manage subscription-based content access. The WPCOM Member plugin allows site administrators to control user accounts, membership levels, and other related functionalities. By supporting various access controls, this plugin is integral in ensuring that only permitted users can access specific site content. Its ease of use and integration with WordPress makes it a popular choice among website managers looking to enhance their site's capabilities.

The SQL Injection vulnerability detected in WPCOM Member Plugin allows attackers to inject malicious SQL queries through the 'user_phone' parameter. Such a flaw can lead unauthorized users to extract sensitive database information by manipulating SQL commands. The vulnerability impacts the integrity and confidentiality of data within the WordPress installation using this plugin. Attackers can exploit this issue to bypass application security layers, thereby accessing restricted areas of the database. The vulnerability results from insufficient escaping and lack of preparation on the parameter in admin-ajax.php. This exposes websites using the WPCOM Member plugin to significant risks.

Technically, the vulnerability arises from the 'user_phone' parameter in HTTP POST requests to admin-ajax.php, where the input is not properly escaped. The crafted payload is constructed to exploit the time-based nature of the SQL Injection, by including a sleep command within the injected SQL query. When executed, this payload prompts an extended delay in server response, indicating successful exploitation. The inclusion of a nonce field also plays a role in verifying the request, though it can be trivially bypassed. This process allows hackers to ascertain the presence of a vulnerability without direct database access. The consequence of this unchecked input manipulation leads to unauthorized database access.

When exploited, the SQL Injection vulnerability may lead to an extensive data breach. Malicious actors could fetch sensitive information such as usernames, email addresses, and hashed passwords. Health data, financial records, or any other sensitive information stored in the database might also be leaked. Privacy violations could result in reputation damage for the site owner, authors, or businesses running on the WordPress platform. Moreover, attackers might leverage this access to escalate privileges or deploy additional attack phases such as data modification or even site takeover. Overall, the impact can range from minor information leaks to severe system compromise.

REFERENCES

Solution Advice
  • Update to the latest version of the WPCOM Member plugin that addresses the SQL Injection vulnerability.
  • Regularly audit and sanitize user inputs to ensure proper escaping and parameter preparation.
  • Implement Web Application Firewalls (WAFs) to filter potentially malicious traffic.
  • Encourage best practices in secure coding to prevent similar vulnerabilities in future development.
  • Conduct regular security testing and vulnerability assessments on platforms and third-party integrations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.