WordPress security by component
Simple Membership
Plugin description
Simple Membership is a WordPress component with 27 published CVE records in this archive. The latest tracked vulnerability was published Jul 06, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
simple-membershipLatest vulnerability
CVE-2026-11855: Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.7.5.
| Safe version |
|
||
|---|---|---|---|
| Jul 06, 2026 |
CVE-2026-11855
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.7.5.
|
4.7.5 |
CVE8.8
NVDPending
|
| Jun 18, 2026 |
CVE-2026-12093
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.7.5.
|
> 4.7.5 |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42663
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.7.2.
|
4.7.3 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-34886
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.7.1.
|
4.7.2 |
CVE7.5
NVDPending
|
| Feb 19, 2026 |
CVE-2026-1461
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25308
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 06, 2025 |
CVE-2025-49333
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Nov 21, 2024 |
CVE-2024-11088
Simple Membership: Sensitive information exposure
Simple Membership is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Oct 24, 2024 |
CVE-2024-49682
Simple Membership: An open redirect
Simple Membership is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE4.7
NVD6.1
|
| May 17, 2024 |
CVE-2023-41957
Simple Membership: Privilege escalation or authentication bypass
Simple Membership is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.6
NVD9.8
|
| May 17, 2024 |
CVE-2023-41956
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| May 14, 2024 |
CVE-2024-4383
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 25, 2024 |
CVE-2024-3730
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 13, 2024 |
CVE-2024-1985
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.7
NVD6.1
|
| Jan 24, 2024 |
CVE-2024-22308
Simple Membership: An open redirect
Simple Membership is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE3.4
NVD6.1
|
| Jan 11, 2024 |
CVE-2023-6882
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Dec 19, 2023 |
CVE-2023-50376
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Sep 06, 2023 |
CVE-2023-4719
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Jan 16, 2023 |
CVE-2022-4469
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 01, 2022 |
CVE-2022-2317
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Aug 01, 2022 |
CVE-2022-2273
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Jun 13, 2022 |
CVE-2022-1724
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Mar 21, 2022 |
CVE-2022-0681
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Feb 28, 2022 |
CVE-2022-0328
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.7
NVD4.7
|
| Aug 14, 2019 |
CVE-2016-10884
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Aug 12, 2019 |
CVE-2017-18499
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jul 28, 2019 |
CVE-2019-14328
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|