CVE-2026-42417: WordPress ARMember Premium plugin <= 7.8 - SQL Injection vulnerability
Published Oct 6, 2026
·Updated
Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.
Affected Software
1 affected component
ARMember ARMember Premium<=7.8
Event History
Oct 6, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
No authentication or user interaction is required. The attack vector is network-based and has low attack complexity.
2
What is the likely security impact if exploitation succeeds?
The supplied severity vector indicates high confidentiality impact, no integrity impact, and low availability impact. The scope is marked as changed.