HIGH
wpinsider-1
CVE published 2026-10-03
CVE-2026-97337
The Simple Membership plugin for WordPress has a vulnerability allowing unauthorized modification of data and sensitive information disclosure in versions up to 4.8.3. This issue arises from the resend-activation and email-activation endpoints being accessible without authentication, nonce, capability, or ownership checks. An attacker can redirect activation and 'registration complete' emails to an arbitr [truncated]