Known CVE
WordPress WPCOM Member <= 1.7.6 - SQL Injection
WPCOM Member plugin for WordPress up to 1.7.6 contains a time-based SQL Injection caused by insufficient escaping and lack of preparation on the 'user_phone' parameter, letting unauthenticated attackers extract sensitive information, exploit requires sending crafted 'user_phone' parameter.
CVE-2025-2221
High2025CVSS 7.5CWE-89
cve2025 · wordpress · wp-plugin · sqli · wpcom-member · unauthenticated
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website