← WordPress Vulnerabilities
WordPress security by component

Simple Membership

Simple Membership creates membership levels, protects content, manages member accounts, and controls access to WordPress site content.

Simple Membership (simple-membership) is a WordPress plugin with 34 published CVE records in this archive. The latest tracked vulnerability was published Sep 17, 2026; the highest published CVSS base score is 9.8.

Plugin slug: simple-membership

CVE-2026-74000: Simple Membership has contributor-level broken access control

Simple Membership through 4.8.2 has broken access control requiring Contributor access according to the description. The disclosed class is a missing or inadequate authorization boundary; the protected data or operation is not named. The CNA vector indicates limited integrity impact without victim interaction. The export does not identify an endpoint, action, function or concrete data fields, so a specific exploit sequence cannot be established. The description requires Contributor access, but the CVSS vector says no privileges; this review retains the explicit role requirement and flags the inconsistency rather than asserting anonymous exploitation. The affected-version data marks 4.8.3 unaffected.

PublishedSep 17, 2026
Known safe version4.8.3
Published vulnerabilities for simple-membership
Safe version
Sep 17, 2026 CVE-2026-74000
Simple Membership has contributor-level broken access control
Simple Membership through 4.8.2 has broken access control requiring Contributor access according to the description. The disclosed class is a missing or inadequate authorization boundary; the protected data or operation is not named. The CNA vector indicates limited integrity impact without victim interaction. The export does not identify an endpoint, action, function or concrete data fields, so a specific exploit sequence cannot be established. The description requires Contributor access, but the CVSS vector says no privileges; this review retains the explicit role requirement and flags the inconsistency rather than asserting anonymous exploitation. The affected-version data marks 4.8.3 unaffected.
4.8.3
CVE5.3
NVDPending
Sep 13, 2026 CVE-2026-88764
Simple Membership trusts a mismatched PayPal membership level
Simple Membership versions before 4.7.8 do not verify that the membership level in a PayPal payment notification matches the level configured for the paid button. A member can pay the price of a lower tier while supplying a higher, more privileged membership level and receive the stronger membership. The authoritative export does not identify the notification endpoint, membership-level field, or button identifier.
4.7.8
CVE5.4
NVDPending
Sep 01, 2026 CVE-2026-77194
Simple Membership permits unauthenticated Multisite Administrator takeover
Simple Membership through 4.8.1 can bind a new membership record to an existing global WordPress user using only a matching username and email, without password or ownership verification, and fails to recognize Administrator roles on child sites. On a Multisite child site with public registration enabled, an unauthenticated attacker can register with an Administrator's identity, use profile editing to replace the victim's global WordPress password, and take over the account. Version 4.8.1 only partially addresses the issue and remains in the affected range.
See mitigation notes
CVE5.3
NVDPending
Aug 06, 2026 CVE-2026-14936
Simple Membership accepts PayPal notifications for the wrong merchant before 4.7.7
Simple Membership before 4.7.7 processes a PayPal Standard IPN without verifying that its merchant or receiver email matches the site's configured PayPal account. An unauthenticated attacker can pay an account they control and use the notification to activate or extend a membership although the site owner received no payment. Version 4.7.7 adds merchant and receiver-email validation. The public IPN endpoint, exact parameter names, membership binding and handler function are not disclosed.
4.7.7
CVE5.3
NVDPending
Aug 06, 2026 CVE-2026-66712
Simple Membership permits unauthenticated access to protected functionality
An unauthenticated visitor can reach a Simple Membership operation that lacks the required authorization check in version 4.7.8 and earlier.
4.7.9
CVE7.5
NVDPending
Aug 03, 2026 CVE-2026-15931
Simple Membership payment approvals let visitors store administrator XSS
Simple Membership before 4.7.8 accepts a subscriber-name value from an unauthenticated payment-approval request, stores it without sanitization and renders it unescaped in the administration dashboard. An unauthenticated attacker can submit script-bearing subscriber data that executes when an Administrator views the affected record.
4.7.8
CVE6.1
NVDPending
Aug 03, 2026 CVE-2026-15930
Simple Membership registration failures can overwrite the primary Administrator
Simple Membership before 4.7.8 does not verify whether WordPress user creation failed before treating the returned value as a user ID for an account update. An unauthenticated attacker can force the failure path so the plugin updates the primary Administrator's account data, including its email address, then use the password-reset flow to take over that account.
4.7.8
CVE9.4
NVDPending
Jul 06, 2026 CVE-2026-11855
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.7.5.
4.7.5
CVE8.8
NVDPending
Jun 18, 2026 CVE-2026-12093
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.7.5.
See mitigation notes
CVE5.3
NVDPending
Jun 15, 2026 CVE-2026-42663
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.7.2.
4.7.3
CVE6.5
NVDPending
Jun 15, 2026 CVE-2026-34886
Simple Membership: Broken access control
Simple Membership is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 4.7.1.
4.7.2
CVE7.5
NVDPending
Feb 19, 2026 CVE-2026-1461
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 19, 2026 CVE-2026-25308
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jun 06, 2025 CVE-2025-49333
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Nov 21, 2024 CVE-2024-11088
Simple Membership: Sensitive information exposure
Simple Membership is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD7.5
Oct 24, 2024 CVE-2024-49682
Simple Membership: An open redirect
Simple Membership is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVD6.1
May 17, 2024 CVE-2023-41957
Simple Membership: Privilege escalation or authentication bypass
Simple Membership is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.6
NVD9.8
May 17, 2024 CVE-2023-41956
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
May 14, 2024 CVE-2024-4383
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 25, 2024 CVE-2024-3730
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Mar 13, 2024 CVE-2024-1985
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.7
NVD6.1
Jan 24, 2024 CVE-2024-22308
Simple Membership: An open redirect
Simple Membership is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE3.4
NVD6.1
Jan 11, 2024 CVE-2023-6882
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Dec 19, 2023 CVE-2023-50376
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Sep 06, 2023 CVE-2023-4719
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Jan 16, 2023 CVE-2022-4469
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 01, 2022 CVE-2022-2317
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD9.8
Aug 01, 2022 CVE-2022-2273
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD8.8
Jun 13, 2022 CVE-2022-1724
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Mar 21, 2022 CVE-2022-0681
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD6.5
Feb 28, 2022 CVE-2022-0328
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD4.7
Aug 14, 2019 CVE-2016-10884
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD8.8
Aug 12, 2019 CVE-2017-18499
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jul 28, 2019 CVE-2019-14328
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVEPending
NVD8.8