Impact
Unattended authenticated bypass exists in Simple Membership plugin through version 4.7.1; it allows attackers to access protected content or assume user identities without credentials. This flaw leads to the compromise of confidentiality, integrity, and potentially availability of the site’s data, and is classified as missing authorization (CWE‑862).
Affected Systems
WordPress installations that use the Simple Membership plugin version 4.7.1 or older are affected. Any site that has not yet upgraded beyond this version falls into risk scope.
Risk and Exploitability
The vulnerability’s CVSS score of 7.5 indicates high severity, however its EPSS probability of less than 1% suggests that exploitation is unlikely to be frequent. The flaw is not present in the CISA KEV catalog. Attackers would most likely exploit the issue by sending requests to the plugin’s administrative endpoints without authenticating, exploiting the plugin’s failure to enforce proper access checks.
OpenCVE Enrichment