WPCOM Member plugin for WordPress up to 1.7.6 contains a time-based SQL Injection caused by insufficient escaping and lack of preparation on the 'user_phone' parameter, letting unauthenticated attackers extract sensitive information, exploit requires sending crafted 'user_phone' parameter.
id: CVE-2025-2221
info:
name: WordPress WPCOM Member <= 1.7.6 - SQL Injection
author: neosmith1
...