Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2.
Published: 2026-10-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Patch
AI Analysis

Impact

The vulnerability allows an unauthorized user to retrieve embedded sensitive data from the Memberful – Membership Plugin when using versions up to and including 1.81.2. This results in the unintended disclosure of confidential system information, breaching confidentiality and potentially enabling further exploitation. The weakness is classified as CWE‑497 (Exposed Content).

Affected Systems

The affected product is the Memberful – Membership Plugin for WordPress. All releases from the earliest available version through 1.81.2 are impacted; version 1.82.0 and later have the issue fixed.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium impact on confidentiality. The lack of an EPSS score means current exploitation probability is unknown, but the absence from KEV suggests no widespread active exploitation has been reported. The attack vector is likely via the web interface of the WordPress site; a user with access to the site could exploit the plugin to download sensitive data. Due to the disclosure nature of the vulnerability, the primary risk is confidentiality loss rather than code execution or denial of service.

Generated by OpenCVE AI on October 5, 2026 at 10:49 UTC.

Remediation

Vendor Solution

Update the WordPress Memberful - Membership Plugin plugin to the latest available version (at least 1.82.0).


OpenCVE Recommended Actions

  • Update the Memberful – Membership Plugin to version 1.82.0 or newer.
  • If an immediate update is not possible, temporarily disable any API endpoints or admin pages that expose sensitive data provided by the plugin.
  • Review and restrict your WordPress site’s user roles so that only trusted administrators can interact access logs for suspicious activity.

Generated by OpenCVE AI on October 5, 2026 at 10:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2.
Title WordPress Memberful - Membership Plugin plugin <= 1.81.2 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T12:57:37.874Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104401

cve-icon Vulnrichment

Updated: 2026-10-05T12:57:34.000Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:08.200

Modified: 2026-10-05T13:16:51.260

Link: CVE-2026-104401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:00:17Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere