PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97337 wpinsider-1 CVE debrief

The Simple Membership plugin for WordPress has a vulnerability allowing unauthorized modification of data and sensitive information disclosure in versions up to 4.8.3. This issue arises from the resend-activation and email-activation endpoints being accessible without authentication, nonce, capability, or ownership checks. An attacker can redirect activation and 'registration complete' emails to an arbitrary address, potentially leading to account activation without user consent.

Vendor
wpinsider-1
Product
Simple Membership
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

WordPress administrators and defenders responsible for securing WordPress installations with the Simple Membership plugin should assess exposure and prioritize remediation. They should verify the plugin version, review security configurations, and monitor for suspicious activity related to account activation and email redirection. Additionally, defenders should consider updating the Simple Membership plugin to a version beyond 4.8.3 and implement compens.

Why it matters

CVE-2026-97337 allows attackers to redirect activation emails and potentially activate accounts without user consent, exposing sensitive information. Defenders should verify exposure, prioritize remediation, and monitor for suspicious activity.

  • Potential for unauthorized account activation
  • Exposure of sensitive information via email redirection
  • Possible disruption of user registration and activation processes
  • Need for verification of plugin version and exposure

Technical summary

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure due to insecure endpoints. The resend-activation and email-activation endpoints lack authentication, nonce, capability, or ownership checks. This allows unauthenticated attackers to redirect activation emails and potentially activate accounts without consent. The vulnerability affects WordPress installations using the Simple Membership plugin version 4.8.3 or earlier, and defenders should assess exposure and prioritize remediation.

Defensive priority

Defenders should prioritize verifying exposure of WordPress installations using the Simple Membership plugin version 4.8.3 or earlier and assess the potential for email redirection and unauthorized account activation.

Recommended defensive actions

  • Verify WordPress installations for Simple Membership plugin version 4.8.3 or earlier
  • Assess potential exposure to email redirection and unauthorized account activation
  • Consider updating the Simple Membership plugin to a version beyond 4.8.3
  • Monitor for suspicious account activation and email forwarding activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability details are based on information from the CVE Program and the National Vulnerability Database (NVD). The Simple Membership plugin's code and vulnerability reports from [email protected] provide additional context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97337 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97337

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97337 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97337

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-init-time-tasks.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-registration.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.