Unauthorized Data Modification and Information Disclosure in Simple Membership Plugin for WordPress
CVE-2026-97337

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2026

What is CVE-2026-97337?

The Simple Membership plugin for WordPress suffers from a vulnerability that allows unauthenticated users to modify sensitive information and data. Through improperly secured email activation endpoints, attackers can exploit the absence of critical security checks such as authentication and nonce verification. By manipulating the email address submitted via an attacker-controlled parameter, malicious users can redirect pending members' activation emails to their own addresses. This not only enables attackers to activate accounts without consent but also allows them to receive sensitive information including usernames and plaintext passwords. Users are urged to update to the latest version to mitigate this risk.

Affected Version(s)

Simple Membership 0 <= 4.8.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuba
.