CVE-2026-7649Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.0.60 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3Technical Details · 2026-05-02: 305-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7649 Time-Based Blind SQL Injection in ARMember WordPress Plugin Versions Up To 4.0.60 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7649

    Post summary

    The text discloses CVE-2026-7649 as a time-based blind SQL injection vulnerability affecting ARMember WordPress plugin versions up to 4.0.60, with no PoC, exploit, or mitigation details provided.

    0000067
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7649 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to time-based blind SQL Injection vi… https://www.cve.org/CVERecord?id=CVE-2026-7649 ----- Traducción: CVE-2026-7649 El … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-7649 against the ARMember WordPress plugin, detailing a time‑based blind SQL injection vulnerability, but provides no PoC, exploit, or patch information.

    0000042
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7649 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to time-based blind SQL Injection vi… https://www.cve.org/CVERecord?id=CVE-2026-7649

    Post summary

    The excerpt announces CVE-2026-7649, describing a time‑based blind SQL injection in the ARMember WordPress plugin, without providing any PoC, exploit, or mitigation details.

    00000188
    57.4K followersView on X

Explore more