Impact
The Simple Membership plugin for WordPress allows an unauthenticated attacker to modify member data and access sensitive information. By targeting the resend-activation and email-activation endpoints in versions up to and including 4.8.3, an attacker can supply a crafted 'email' parameter that overrides the recipient address. This results in the activation email and the subsequent registration complete email—which contains the member’s username and plaintext password—being sent to an attacker‑controlled address. The attacker can then activate the pending member’s account without consent, effectively taking over the account and exposing personal credentials.
Affected Systems
WordPress sites running the Simple Membership plugin version 4.8.3 or earlier are affected. The vulnerability does not depend on user role or administrative privileges; any installation of the plugin containing the vulnerable code paths is impacted.
Risk and Exploitability
The issue carries a CVSS score of 7.5, indicating a high‑severity risk. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, though the potential for account takeover and credential disclosure makes it a serious threat. Typical exploitation would involve an unauthenticated HTTP request to the plugin’s front‑end activation endpoints, and no additional authentication or privilege checks are required.
OpenCVE Enrichment