Impact
The Simple Membership plugin for WordPress allows an optional auto‑login‑after‑registration feature that, in versions prior to 4.8.3, inadvertently sends a new member's plaintext password in the URL query string. This places the password in the browser history and within any web server, proxy, or CDN access logs that capture the full request, exposing the credential to anyone who can read those artifacts.
Affected Systems
Vulnerability affects the Simple Membership WordPress plugin when the version is older than 4.8.3. The plugin is distributed to sites running WordPress; any installation that has not upgraded to 4.8.3 or higher is potentially exposed.
Risk and Exploitability
The exploitation requires that an attacker be able to read browser history or logs that contain the URL. No network‑based attack vector is required. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation yet. However, because the plaintext credentials can be retrieved from logs, the impact is the compromise of user accounts and potential lateral movement if the same credentials are reused. The lack of a public exploit, coupled with the absence from KEV, suggests the risk is moderate to high depending on the exposure of logging infrastructure.
OpenCVE Enrichment