CVE-2026-49077: WordPress WP eMember plugin <= v10.2.2 - Sensitive Data Exposure vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data.
This issue affects WP eMember: from n/a through v10.2.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
WP eMemberfrom your environment.Uninstall the affected WP eMember WordPress plugin (versions <= v10.2.2) if it is not required.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49077?
CVE-2026-49077 has a medium severity rating of 5.3.
How do I fix CVE-2026-49077?
To fix CVE-2026-49077, upgrade the WP eMember plugin to version 10.2.3 or later.
What software is affected by CVE-2026-49077?
CVE-2026-49077 affects the Tips and Tricks HQ WP eMember plugin version up to 10.2.2.
What type of vulnerability is CVE-2026-49077?
CVE-2026-49077 is a Sensitive Data Exposure vulnerability.
What can attackers do with CVE-2026-49077?
Attackers can retrieve embedded sensitive data due to vulnerability in the WP eMember plugin.