Simple Membership
Simple Membership creates membership levels, protects content, manages member accounts, and controls access to WordPress site content.
Simple Membership (simple-membership) is a WordPress plugin with 32 published CVE records in this archive. The latest tracked vulnerability was published Sep 01, 2026; the highest published CVSS base score is 9.8.
simple-membershipCVE-2026-77194: Simple Membership permits unauthenticated Multisite Administrator takeover
Simple Membership through 4.8.1 can bind a new membership record to an existing global WordPress user using only a matching username and email, without password or ownership verification, and fails to recognize Administrator roles on child sites. On a Multisite child site with public registration enabled, an unauthenticated attacker can register with an Administrator's identity, use profile editing to replace the victim's global WordPress password, and take over the account. Version 4.8.1 only partially addresses the issue and remains in the affected range.
| Safe version |
|
||
|---|---|---|---|
| Sep 01, 2026 |
CVE-2026-77194
Simple Membership permits unauthenticated Multisite Administrator takeover
Simple Membership through 4.8.1 can bind a new membership record to an existing global WordPress user using only a matching username and email, without password or ownership verification, and fails to recognize Administrator roles on child sites. On a Multisite child site with public registration enabled, an unauthenticated attacker can register with an Administrator's identity, use profile editing to replace the victim's global WordPress password, and take over the account. Version 4.8.1 only partially addresses the issue and remains in the affected range.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 06, 2026 |
CVE-2026-14936
Simple Membership accepts PayPal notifications for the wrong merchant before 4.7.7
Simple Membership before 4.7.7 processes a PayPal Standard IPN without verifying that its merchant or receiver email matches the site's configured PayPal account. An unauthenticated attacker can pay an account they control and use the notification to activate or extend a membership although the site owner received no payment. Version 4.7.7 adds merchant and receiver-email validation. The public IPN endpoint, exact parameter names, membership binding and handler function are not disclosed.
|
4.7.7 |
CVE5.3
NVDPending
|
| Aug 06, 2026 |
CVE-2026-66712
Simple Membership permits unauthenticated access to protected functionality
An unauthenticated visitor can reach a Simple Membership operation that lacks the required authorization check in version 4.7.8 and earlier.
|
4.7.9 |
CVE7.5
NVDPending
|
| Aug 03, 2026 |
CVE-2026-15931
Simple Membership payment approvals let visitors store administrator XSS
Simple Membership before 4.7.8 accepts a subscriber-name value from an unauthenticated payment-approval request, stores it without sanitization and renders it unescaped in the administration dashboard. An unauthenticated attacker can submit script-bearing subscriber data that executes when an Administrator views the affected record.
|
4.7.8 |
CVE6.1
NVDPending
|
| Aug 03, 2026 |
CVE-2026-15930
Simple Membership registration failures can overwrite the primary Administrator
Simple Membership before 4.7.8 does not verify whether WordPress user creation failed before treating the returned value as a user ID for an account update. An unauthenticated attacker can force the failure path so the plugin updates the primary Administrator's account data, including its email address, then use the password-reset flow to take over that account.
|
4.7.8 |
CVE9.4
NVDPending
|
| Jul 06, 2026 |
CVE-2026-11855
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.7.5.
|
4.7.5 |
CVE8.8
NVDPending
|
| Jun 18, 2026 |
CVE-2026-12093
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.7.5.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-42663
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.7.2.
|
4.7.3 |
CVE6.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-34886
Simple Membership: Broken access control
Simple Membership is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 4.7.1.
|
4.7.2 |
CVE7.5
NVDPending
|
| Feb 19, 2026 |
CVE-2026-1461
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25308
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 06, 2025 |
CVE-2025-49333
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Nov 21, 2024 |
CVE-2024-11088
Simple Membership: Sensitive information exposure
Simple Membership is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Oct 24, 2024 |
CVE-2024-49682
Simple Membership: An open redirect
Simple Membership is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE4.7
NVD6.1
|
| May 17, 2024 |
CVE-2023-41957
Simple Membership: Privilege escalation or authentication bypass
Simple Membership is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.6
NVD9.8
|
| May 17, 2024 |
CVE-2023-41956
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| May 14, 2024 |
CVE-2024-4383
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 25, 2024 |
CVE-2024-3730
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 13, 2024 |
CVE-2024-1985
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.7
NVD6.1
|
| Jan 24, 2024 |
CVE-2024-22308
Simple Membership: An open redirect
Simple Membership is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
|
See mitigation notes |
CVE3.4
NVD6.1
|
| Jan 11, 2024 |
CVE-2023-6882
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Dec 19, 2023 |
CVE-2023-50376
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Sep 06, 2023 |
CVE-2023-4719
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Jan 16, 2023 |
CVE-2022-4469
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Aug 01, 2022 |
CVE-2022-2317
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD9.8
|
| Aug 01, 2022 |
CVE-2022-2273
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Jun 13, 2022 |
CVE-2022-1724
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Mar 21, 2022 |
CVE-2022-0681
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Feb 28, 2022 |
CVE-2022-0328
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD4.7
|
| Aug 14, 2019 |
CVE-2016-10884
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Aug 12, 2019 |
CVE-2017-18499
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Jul 28, 2019 |
CVE-2019-14328
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD8.8
|