Skip to content
Threat Feed
high advisory

Unauthenticated Account Takeover and Data Disclosure in Simple Membership Plugin for WordPress

The Simple Membership plugin for WordPress is vulnerable to unauthenticated account activation and credential disclosure due to insufficient input validation in activation-related endpoints.

CVE search metadata

CVE search record: CVE-2026-97337. Severity: high. CVSS: 7.5. KEV: no. Product: Simple Membership (<= 4.8.3). Brief: Unauthenticated Account Takeover and Data Disclosure in Simple Membership Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-simple-membership-vulnerability/

The Simple Membership plugin for WordPress (versions 4.8.3 and earlier) contains a critical authentication bypass vulnerability stemming from the resend-activation and email-activation endpoints. These endpoints, processed via the SwpmInitTimeTasks::check_and_do_email_activation() function during frontend initialization, lack necessary authentication, nonce validation, and capability checks. An attacker can exploit this by submitting an arbitrary email address via the $_POST['email'] parameter. This action overrides the legitimate member's registered email address and causes the application to send registration-complete emails - which include the user's username and plaintext password - to an attacker-controlled destination. This vulnerability enables unauthorized account activation and the collection of sensitive credentials, providing a pathway for account takeover.

Impact

Successful exploitation allows unauthenticated attackers to hijack member registrations, gain unauthorized access to accounts, and harvest plaintext credentials. This impacts any WordPress site utilizing the Simple Membership plugin for user management, potentially leading to unauthorized data access or escalation of privileges depending on the target account's role.

Recommendation

Update the Simple Membership plugin to the latest version, ensuring the patch for CVE-2026-97337 is applied. Prioritize monitoring web server access logs for anomalous POST requests directed at the plugin's activation endpoints from unexpected sources.


Immediate actions

Upgrade Simple Membership plugin to a version addressing CVE-2026-97337.

IT Operations 48h

Mitigations

Upgrade Simple Membership to the latest patched release.

immediate IT Operations

CVE-2026-97337

Detection coverage 1

Detect CVE-2026-97337 Exploitation - POST Request to Activation Endpoints

high

Detects potential exploitation of CVE-2026-97337 by identifying unauthenticated POST requests to the Simple Membership activation endpoints with an email parameter.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →