CVE-2026-105317: WordPress Paid Member Subscriptions plugin <= 3.1.1 - SQL Injection vulnerability
Published Oct 6, 2026
·Updated
Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.
Affected Software
1 affected component
Cozmoslabs Paid Member Subscriptions<=3.1.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Paid Member Subscriptionsto a version that resolves this vulnerability.Fixed in 3.1.2
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack vector requires low privileges (PR:L), consistent with exploitation by a subscriber-level authenticated user. It is network-accessible, has low attack complexity, and does not require user interaction.
2
What is the expected security impact if exploitation succeeds?
The severity vector indicates high confidentiality impact, low availability impact, and no integrity impact. It also indicates that the vulnerability can affect a security scope beyond the initially vulnerable component (S:C).