PT-2026-104512 · WordPress · Simple Membership
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Simple Membership plugin for WordPress versions prior to 4.8.4
Description
Unauthorized modification of data and sensitive information disclosure occur via the 'resend-activation' and 'email-activation' endpoints. These endpoints are dispatched from the
check and do email activation() function within SwpmInitTimeTasks during frontend initialization without authentication, nonce, capability, or ownership checks. An unauthenticated attacker can use the email parameter in the $ POST request to override a member's registered address. This allows the redirection of pending activation emails and subsequent registration completion emails, which contain the member's username and plaintext password, to an address controlled by the attacker, enabling unauthorized account activation.Recommendations
Update the plugin to version 4.8.4 or later.
Restrict access to the 'resend-activation' and 'email-activation' endpoints as a temporary mitigation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Membership