Impact
A flaw in the Simple Membership WordPress plugin before version 4.7.8 allows an attacker to submit a PayPal IPN that carries a subscription reference for a lower‑priced membership while specifying a higher, more privileged membership level. The plugin fails to verify that the level sent in the notification matches the configured level for the paid button, permitting an attacker to receive privileges beyond the amount paid. This constitutes a privilege escalation that can impact the confidentiality and integrity of the site’s membership data and the services available to members.
Affected Systems
The vulnerability affects the Simple Membership WordPress plugin, an unknown vendor, for all releases prior to 4.7.8. WordPress systems running the plugin before that version are at risk.
Risk and Exploitability
Based on the description, the likely attack vector is a crafted PayPal IPN message sent to the site. The CVSS score of 5.4 indicates moderate severity, and the EPSS score of <1% indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the defect permits an attacker to modify the membership level without additional credential or access requirements, the potential impact is significant if exploitation occurs, but the likelihood is low as the EPSS suggests. The exact likelihood cannot be precisely determined.
OpenCVE Enrichment