OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-105317

HIGH · CVSS 8.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-10-06 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A SQL injection vulnerability exists in the Paid Member Subscriptions plugin for versions up to 3.1.1, allowing attackers to manipulate database queries and potentially gain unauthorized access to sensitive data. This high-severity flaw poses a significant risk to any site utilizing the affected plugin, making it crucial for administrators and security teams to prioritize immediate patching or mitigation efforts.

CVE
CVE-2026-105317
Severity
HIGH
CVSS
8.5
EPSS
0.28%

Original NVD Description

Subscriber SQL Injection in Paid Member Subscriptions <= 3.1.1 versions.