Description
The Simple Membership WordPress plugin before 4.8.3 does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration feature is enabled, exposing the credential in browser history and in web server, proxy, and CDN access logs to anyone able to read them.
Published: 2026-10-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Disclosure
Action: Patch
AI Analysis

Impact

The Simple Membership plugin for WordPress allows an optional auto‑login‑after‑registration feature that, in versions prior to 4.8.3, inadvertently sends a new member's plaintext password in the URL query string. This places the password in the browser history and within any web server, proxy, or CDN access logs that capture the full request, exposing the credential to anyone who can read those artifacts.

Affected Systems

Vulnerability affects the Simple Membership WordPress plugin when the version is older than 4.8.3. The plugin is distributed to sites running WordPress; any installation that has not upgraded to 4.8.3 or higher is potentially exposed.

Risk and Exploitability

The exploitation requires that an attacker be able to read browser history or logs that contain the URL. No network‑based attack vector is required. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation yet. However, because the plaintext credentials can be retrieved from logs, the impact is the compromise of user accounts and potential lateral movement if the same credentials are reused. The lack of a public exploit, coupled with the absence from KEV, suggests the risk is moderate to high depending on the exposure of logging infrastructure.

Generated by OpenCVE AI on October 11, 2026 at 07:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Simple Membership WordPress plugin to version 4.8.3 or later.
  • If an immediate upgrade is not possible, disable the auto‑login-after‑registration feature until the plugin has been updated.
  • Review web server, proxy, and CDN access logs for exposed passwords; reset any affected users’ passwords immediately.
  • Implement a log sanitization or redaction policy to prevent passwords from appearing in logs.

Generated by OpenCVE AI on October 11, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-532

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Simple Membership WordPress plugin before 4.8.3 does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration feature is enabled, exposing the credential in browser history and in web server, proxy, and CDN access logs to anyone able to read them.
Title Simple Membership < 4.8.3 - Newly Registered Member Password Disclosure via URL Query String
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:43.112Z

Reserved: 2026-09-10T07:45:39.142Z

Link: CVE-2026-88785

cve-icon Vulnrichment

Updated: 2026-10-11T11:19:01.649Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:27.030

Modified: 2026-10-11T12:17:25.547

Link: CVE-2026-88785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:45:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-532

    Insertion of Sensitive Information into Log File