CVE-2025-49870: WordPress Paid Member Subscriptions plugin <= 2.15.1 - SQL Injection Vulnerability
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions allows SQL Injection. This issue affects Paid Member Subscriptions: from n/a through 2.15.1.
Other sources
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows SQL Injection.This issue affects Paid Member Subscriptions: from n/a through <= 2.15.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49870?
The severity of CVE-2025-49870 is critical due to its potential for SQL Injection exploits.
How do I fix CVE-2025-49870?
To fix CVE-2025-49870, update the Paid Member Subscriptions plugin to version 2.15.2 or later.
What applications are affected by CVE-2025-49870?
CVE-2025-49870 affects Cozmoslabs Paid Member Subscriptions versions up to and including 2.15.1.
Could CVE-2025-49870 allow unauthorized access to my database?
Yes, CVE-2025-49870 could allow attackers to perform unauthorized SQL queries, potentially compromising your database.
Is CVE-2025-49870 actively being exploited?
At this time, there are no publicly known active exploits for CVE-2025-49870, but it remains a significant risk.