Description
The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST['email'] parameter (overriding the member's registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member's activation email — and the follow-up 'registration complete' email containing the member's username and plaintext password — to an attacker-chosen address, and to then activate that member's account without their consent.
Published: 2026-10-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated account takeover and sensitive information disclosure
Action: Immediate Patch
AI Analysis

Impact

The Simple Membership plugin for WordPress allows an unauthenticated attacker to modify member data and access sensitive information. By targeting the resend-activation and email-activation endpoints in versions up to and including 4.8.3, an attacker can supply a crafted 'email' parameter that overrides the recipient address. This results in the activation email and the subsequent registration complete email—which contains the member’s username and plaintext password—being sent to an attacker‑controlled address. The attacker can then activate the pending member’s account without consent, effectively taking over the account and exposing personal credentials.

Affected Systems

WordPress sites running the Simple Membership plugin version 4.8.3 or earlier are affected. The vulnerability does not depend on user role or administrative privileges; any installation of the plugin containing the vulnerable code paths is impacted.

Risk and Exploitability

The issue carries a CVSS score of 7.5, indicating a high‑severity risk. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, though the potential for account takeover and credential disclosure makes it a serious threat. Typical exploitation would involve an unauthenticated HTTP request to the plugin’s front‑end activation endpoints, and no additional authentication or privilege checks are required.

Generated by OpenCVE AI on October 3, 2026 at 06:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Simple Membership to the latest version (greater than 4.8.3) as soon as possible.
  • If an upgrade is not possible immediately, restrict access to the resend-activation and email-activation endpoints by blocking or filtering the endpoints with a web‑application firewall or IP restriction. This prevents unauthenticated users from reaching the vulnerable code paths.
  • Verify no pending activations exist for unrecognized email addresses and delete any accounts that may have been activated via malicious emails.

Generated by OpenCVE AI on October 3, 2026 at 06:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST['email'] parameter (overriding the member's registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member's activation email — and the follow-up 'registration complete' email containing the member's username and plaintext password — to an attacker-chosen address, and to then activate that member's account without their consent.
Title Simple Membership <= 4.8.3 - Missing Authorization to Unauthenticated Account Takeover and Sensitive Information Disclosure via 'email' Parameter on Activation Endpoints
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:44.331Z

Reserved: 2026-09-24T12:22:41.848Z

Link: CVE-2026-97337

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:16.717Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:48.943

Modified: 2026-10-03T16:16:48.693

Link: CVE-2026-97337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:30:18Z

Weaknesses