PT-2026-104512 · WordPress · Simple Membership

·

CVE-2026-97337

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Simple Membership plugin for WordPress versions prior to 4.8.4
Description Unauthorized modification of data and sensitive information disclosure occur via the 'resend-activation' and 'email-activation' endpoints. These endpoints are dispatched from the check and do email activation() function within SwpmInitTimeTasks during frontend initialization without authentication, nonce, capability, or ownership checks. An unauthenticated attacker can use the email parameter in the $ POST request to override a member's registered address. This allows the redirection of pending activation emails and subsequent registration completion emails, which contain the member's username and plaintext password, to an address controlled by the attacker, enabling unauthorized account activation.
Recommendations Update the plugin to version 4.8.4 or later. Restrict access to the 'resend-activation' and 'email-activation' endpoints as a temporary mitigation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97337

Affected Products

Simple Membership