← WordPress Vulnerabilities
WordPress security by component

Simple Membership

Simple Membership is a WordPress component with 27 published CVE records in this archive. The latest tracked vulnerability was published Jul 06, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: simple-membership

CVE-2026-11855: Simple Membership: A security weakness

Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.7.5.

PublishedJul 06, 2026
Known safe version4.7.5
Safe version
Jul 06, 2026 CVE-2026-11855
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.7.5.
4.7.5
CVE8.8
NVDPending
Jun 18, 2026 CVE-2026-12093
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 4.7.5.
> 4.7.5
CVE5.3
NVDPending
Jun 15, 2026 CVE-2026-42663
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 4.7.2.
4.7.3
CVE6.5
NVDPending
Jun 15, 2026 CVE-2026-34886
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 4.7.1.
4.7.2
CVE7.5
NVDPending
Feb 19, 2026 CVE-2026-1461
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 19, 2026 CVE-2026-25308
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jun 06, 2025 CVE-2025-49333
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Nov 21, 2024 CVE-2024-11088
Simple Membership: Sensitive information exposure
Simple Membership is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD7.5
Oct 24, 2024 CVE-2024-49682
Simple Membership: An open redirect
Simple Membership is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVD6.1
May 17, 2024 CVE-2023-41957
Simple Membership: Privilege escalation or authentication bypass
Simple Membership is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.6
NVD9.8
May 17, 2024 CVE-2023-41956
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
May 14, 2024 CVE-2024-4383
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Apr 25, 2024 CVE-2024-3730
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Mar 13, 2024 CVE-2024-1985
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.7
NVD6.1
Jan 24, 2024 CVE-2024-22308
Simple Membership: An open redirect
Simple Membership is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE3.4
NVD6.1
Jan 11, 2024 CVE-2023-6882
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Dec 19, 2023 CVE-2023-50376
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Sep 06, 2023 CVE-2023-4719
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Jan 16, 2023 CVE-2022-4469
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 01, 2022 CVE-2022-2317
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Aug 01, 2022 CVE-2022-2273
Simple Membership: A security weakness
Simple Membership is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
Jun 13, 2022 CVE-2022-1724
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 21, 2022 CVE-2022-0681
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD6.5
Feb 28, 2022 CVE-2022-0328
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.7
NVD4.7
Aug 14, 2019 CVE-2016-10884
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Aug 12, 2019 CVE-2017-18499
Simple Membership: Cross-site scripting
Simple Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jul 28, 2019 CVE-2019-14328
Simple Membership: Cross-site request forgery
Simple Membership is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8