Unauthenticated Account Takeover and Data Disclosure in Simple Membership Plugin for WordPress
The Simple Membership plugin for WordPress is vulnerable to unauthenticated account activation and credential disclosure due to insufficient input validation in activation-related endpoints.
CVE search metadata
CVE search record: CVE-2026-97337. Severity: high. CVSS: 7.5. KEV: no. Product: Simple Membership (<= 4.8.3). Brief: Unauthenticated Account Takeover and Data Disclosure in Simple Membership Plugin for WordPress. Brief link: https://feed.craftedsignal.io/briefs/2026-10-simple-membership-vulnerability/
The Simple Membership plugin for WordPress (versions 4.8.3 and earlier) contains a critical authentication bypass vulnerability stemming from the resend-activation and email-activation endpoints. These endpoints, processed via the SwpmInitTimeTasks::check_and_do_email_activation() function during frontend initialization, lack necessary authentication, nonce validation, and capability checks. An attacker can exploit this by submitting an arbitrary email address via the $_POST['email'] parameter. This action overrides the legitimate member's registered email address and causes the application to send registration-complete emails - which include the user's username and plaintext password - to an attacker-controlled destination. This vulnerability enables unauthorized account activation and the collection of sensitive credentials, providing a pathway for account takeover.
Impact
Successful exploitation allows unauthenticated attackers to hijack member registrations, gain unauthorized access to accounts, and harvest plaintext credentials. This impacts any WordPress site utilizing the Simple Membership plugin for user management, potentially leading to unauthorized data access or escalation of privileges depending on the target account's role.
Recommendation
Update the Simple Membership plugin to the latest version, ensuring the patch for CVE-2026-97337 is applied. Prioritize monitoring web server access logs for anomalous POST requests directed at the plugin's activation endpoints from unexpected sources.
Immediate actions
Upgrade Simple Membership plugin to a version addressing CVE-2026-97337.
Mitigations
Upgrade Simple Membership to the latest patched release.
CVE-2026-97337
Detection coverage 1
Detect CVE-2026-97337 Exploitation - POST Request to Activation Endpoints
highDetects potential exploitation of CVE-2026-97337 by identifying unauthenticated POST requests to the Simple Membership activation endpoints with an email parameter.
Detection queries are available on the platform. Get full rules →