Description
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.
Published: 2026-08-03
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Simple Membership WordPress plugin fails to verify whether a user registration succeeded before using the returned value as a user ID to update an account. This logic flaw allows an unauthenticated attacker to register a new user with the same username as the site’s original administrator. The plugin then overwrites the administrator’s account data, including the email address, and the attacker can immediately trigger a password reset to take over the account. The result is full control of the WordPress site’s administrative privileges. The weakness is an improper access control flaw that permits privilege escalation.

Affected Systems

WordPress sites using the Simple Membership plugin version 4.7.7 or earlier are vulnerable. No specific vendor name is provided beyond the plugin identifier. Sites must confirm they are running a pre‑4.7.8 release to determine risk.

Risk and Exploitability

The vulnerability can be exploited by any unauthenticated user who can submit a registration request, so network restrictions are minimal. Exploit probability is considered low due to the EPSS score of < 1%, yet the absence of authentication and the clear path to takeover render the risk high. The vulnerability is not listed in the CISA KEV catalog. The CVSS score of 9.4 indicates extremely high severity, underscoring the urgent need for remediation.

Generated by OpenCVE AI on August 4, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Simple Membership to version 4.7.8 or later. The official patch removes the logic error that allows username collision to overwrite the primary administrator.
  • Pre‑upgrade, disable new user registration or restrict it to administrative accounts so that unauthenticated users cannot register a conflicting username. This limits the attack surface until the plugin can be updated.
  • If upgrading is not immediately possible, prevent the password reset flow for newly created accounts that coincide with existing administrators. Force administrators to reset passwords manually to avoid exploitation.

Generated by OpenCVE AI on August 4, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Simple-membership-plugin
Simple-membership-plugin simple Membership
Wordpress
Wordpress wordpress
Vendors & Products Simple-membership-plugin
Simple-membership-plugin simple Membership
Wordpress
Wordpress wordpress

Mon, 03 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.
Title Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision
References

Subscriptions

Simple-membership-plugin Simple Membership
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-03T17:30:59.804Z

Reserved: 2026-07-16T07:28:21.275Z

Link: CVE-2026-15930

cve-icon Vulnrichment

Updated: 2026-08-03T17:16:59.904Z

cve-icon NVD

Status : Received

Published: 2026-08-03T07:16:40.310

Modified: 2026-08-03T18:16:36.213

Link: CVE-2026-15930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:45:02Z

Weaknesses