<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:simple_membership_project:simple_membership:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3asimple_membership_projectsimple_membershipwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 06:54:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3asimple_membership_projectsimple_membershipwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Account Takeover and Data Disclosure in Simple Membership Plugin for WordPress</title><link>https://feed.craftedsignal.io/briefs/2026-10-simple-membership-vulnerability/</link><pubDate>Sat, 03 Oct 2026 06:54:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-simple-membership-vulnerability/</guid><description>The Simple Membership plugin for WordPress is vulnerable to unauthenticated account activation and credential disclosure due to insufficient input validation in activation-related endpoints.</description><content:encoded><![CDATA[<p>The Simple Membership plugin for WordPress (versions 4.8.3 and earlier) contains a critical authentication bypass vulnerability stemming from the resend-activation and email-activation endpoints. These endpoints, processed via the SwpmInitTimeTasks::check_and_do_email_activation() function during frontend initialization, lack necessary authentication, nonce validation, and capability checks. An attacker can exploit this by submitting an arbitrary email address via the $_POST['email'] parameter. This action overrides the legitimate member's registered email address and causes the application to send registration-complete emails - which include the user's username and plaintext password - to an attacker-controlled destination. This vulnerability enables unauthorized account activation and the collection of sensitive credentials, providing a pathway for account takeover.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to hijack member registrations, gain unauthorized access to accounts, and harvest plaintext credentials. This impacts any WordPress site utilizing the Simple Membership plugin for user management, potentially leading to unauthorized data access or escalation of privileges depending on the target account's role.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Simple Membership plugin to the latest version, ensuring the patch for CVE-2026-97337 is applied. Prioritize monitoring web server access logs for anomalous POST requests directed at the plugin's activation endpoints from unexpected sources.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>authentication-bypass</category></item></channel></rss>