Description
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'country' parameter in all versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers may also exploit this vulnerability when the plugin's Enable Free Membership feature is turned on, as it permits anonymous front-end registration and profile submission.
Published: 2026-10-10
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

A stored cross‑site scripting flaw in the country field exposes it to injection of arbitrary scripts. When an authenticated user with subscriber‑level or higher privileges submits a malicious payload, the text is stored and rendered without proper sanitization, causing the script to execute in any browser that visits the page. The vulnerability thus permits privilege‑escalated script execution that could steal or manipulate session data and compromise confidentiality and integrity of user interactions. Even users with anonymous front‑end registration can exploit the flaw if the free membership feature is enabled, broadening the potential impact to unauthenticated users.

Affected Systems

The flaw affects the Simple Membership WordPress plugin for all releases up to and including 4.8.4. End‑users running any of these versions on their WordPress sites are vulnerable; the issue is resolved in 4.8.5 and later.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity while the EPSS score is not available, suggesting limited information about active exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is authenticated subscriber‑level access, though unauthenticated exploitation is possible when the free membership option is enabled. An attacker would need to submit a malicious value for the country field via the member form, after which the script would run in the browsers of any visitor to the affected pages.

Generated by OpenCVE AI on October 10, 2026 at 08:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Simple Membership plugin to version 4.8.5 or later.
  • If an immediate upgrade is not possible, disable the "Enable Free Membership" option to block unauthenticated form submissions.
  • Verify that any custom code or hooks rendering the country field perform proper escaping or sanitization to prevent script injection.

Generated by OpenCVE AI on October 10, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
Description The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'country' parameter in all versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers may also exploit this vulnerability when the plugin's Enable Free Membership feature is turned on, as it permits anonymous front-end registration and profile submission.
Title Simple Membership <= 4.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Country Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T06:40:16.716Z

Reserved: 2026-09-30T14:55:37.102Z

Link: CVE-2026-103427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T07:16:40.120

Modified: 2026-10-10T07:16:40.120

Link: CVE-2026-103427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T08:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')