ARMember WordPress Plugin Time-Based Blind SQL Injection Vulnerability

Vulnerability

A time-based blind SQL injection vulnerability has been identified in the ARMember WordPress plugin, specifically in versions through 4.0.60. The issue arises in the 'orderby' parameter, where insufficient escaping of user-supplied data allows unauthenticated attackers to inject additional SQL queries. This exploitation could lead to the extraction of sensitive information from the database.

Impact

Exploitation of this vulnerability could allow an attacker to execute arbitrary SQL commands, potentially leading to unauthorized data access or manipulation.

Reproduction

To reproduce this vulnerability, send a request to a vulnerable WordPress site with the ARMember plugin active. Include the 'orderby' parameter in the request. The lack of proper input sanitization will allow the injection of malicious SQL that could be executed by the database, potentially exposing sensitive information.

Added: May 2, 2026, 8:20 AM
Updated: May 2, 2026, 8:20 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
2.5
exploitability
9.3
remediation
0.0
relevance
7.2
threat
4.8
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.