PatchSiren

WPMart CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WPMart CVE published 2026-05-07

CVE-2025-68060

A SQL injection vulnerability exists in the Team Member plugin for WordPress, allowing for blind SQL injection attacks. The issue affects Team Member versions from n/a through 8.5. This vulnerability could lead to potential data breaches due to unauthorized database access and increased risk of lateral movement within compromised networks. Defenders should prioritize verifying exposure and applying patche [truncated]