Membership Activation Flaw in Simple Membership Plugin by WordPress
CVE-2026-14936
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 6 August 2026
Badges
What is CVE-2026-14936?
The Simple Membership plugin for WordPress, prior to version 4.7.7, exposes a vulnerability that allows unauthenticated individuals to activate or extend memberships. This occurs because the plugin fails to verify that a PayPal payment notification is directed to the configured merchant account of a site. As a result, attackers can exploit this flaw by sending payment notifications from arbitrary PayPal accounts, gaining unauthorized access to membership features.
Affected Version(s)
Simple Membership 0 < 4.7.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved