{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/simple-membership--4.8.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:simple_membership_project:simple_membership:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-97337"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Simple Membership (\u003c= 4.8.3)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","authentication-bypass"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Simple Membership plugin for WordPress (versions 4.8.3 and earlier) contains a critical authentication bypass vulnerability stemming from the resend-activation and email-activation endpoints. These endpoints, processed via the SwpmInitTimeTasks::check_and_do_email_activation() function during frontend initialization, lack necessary authentication, nonce validation, and capability checks. An attacker can exploit this by submitting an arbitrary email address via the $_POST['email'] parameter. This action overrides the legitimate member's registered email address and causes the application to send registration-complete emails - which include the user's username and plaintext password - to an attacker-controlled destination. This vulnerability enables unauthorized account activation and the collection of sensitive credentials, providing a pathway for account takeover.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to hijack member registrations, gain unauthorized access to accounts, and harvest plaintext credentials. This impacts any WordPress site utilizing the Simple Membership plugin for user management, potentially leading to unauthorized data access or escalation of privileges depending on the target account's role.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Simple Membership plugin to the latest version, ensuring the patch for CVE-2026-97337 is applied. Prioritize monitoring web server access logs for anomalous POST requests directed at the plugin's activation endpoints from unexpected sources.\u003c/p\u003e\n","date_modified":"2026-10-03T06:54:48Z","date_published":"2026-10-03T06:54:48Z","id":"https://feed.craftedsignal.io/briefs/2026-10-simple-membership-vulnerability/","summary":"The Simple Membership plugin for WordPress is vulnerable to unauthenticated account activation and credential disclosure due to insufficient input validation in activation-related endpoints.","title":"Unauthenticated Account Takeover and Data Disclosure in Simple Membership Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-10-simple-membership-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Simple Membership (\u003c= 4.8.3)","version":"https://jsonfeed.org/version/1.1"}