Unauthorized Data Modification and Information Disclosure in Simple Membership Plugin for WordPress
CVE-2026-97337
7.5HIGH
What is CVE-2026-97337?
The Simple Membership plugin for WordPress suffers from a vulnerability that allows unauthenticated users to modify sensitive information and data. Through improperly secured email activation endpoints, attackers can exploit the absence of critical security checks such as authentication and nonce verification. By manipulating the email address submitted via an attacker-controlled parameter, malicious users can redirect pending members' activation emails to their own addresses. This not only enables attackers to activate accounts without consent but also allows them to receive sensitive information including usernames and plaintext passwords. Users are urged to update to the latest version to mitigate this risk.
Affected Version(s)
Simple Membership 0 <= 4.8.3