PatchSiren cyber security CVE debrief
CVE-2026-97337 wpinsider-1 CVE debrief
The Simple Membership plugin for WordPress has a vulnerability allowing unauthorized modification of data and sensitive information disclosure in versions up to 4.8.3. This issue arises from the resend-activation and email-activation endpoints being accessible without authentication, nonce, capability, or ownership checks. An attacker can redirect activation and 'registration complete' emails to an arbitrary address, potentially leading to account activation without user consent.
- Vendor
- wpinsider-1
- Product
- Simple Membership
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
WordPress administrators and defenders responsible for securing WordPress installations with the Simple Membership plugin should assess exposure and prioritize remediation. They should verify the plugin version, review security configurations, and monitor for suspicious activity related to account activation and email redirection. Additionally, defenders should consider updating the Simple Membership plugin to a version beyond 4.8.3 and implement compens.
Why it matters
CVE-2026-97337 allows attackers to redirect activation emails and potentially activate accounts without user consent, exposing sensitive information. Defenders should verify exposure, prioritize remediation, and monitor for suspicious activity.
- Potential for unauthorized account activation
- Exposure of sensitive information via email redirection
- Possible disruption of user registration and activation processes
- Need for verification of plugin version and exposure
Technical summary
The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure due to insecure endpoints. The resend-activation and email-activation endpoints lack authentication, nonce, capability, or ownership checks. This allows unauthenticated attackers to redirect activation emails and potentially activate accounts without consent. The vulnerability affects WordPress installations using the Simple Membership plugin version 4.8.3 or earlier, and defenders should assess exposure and prioritize remediation.
Defensive priority
Defenders should prioritize verifying exposure of WordPress installations using the Simple Membership plugin version 4.8.3 or earlier and assess the potential for email redirection and unauthorized account activation.
Recommended defensive actions
- Verify WordPress installations for Simple Membership plugin version 4.8.3 or earlier
- Assess potential exposure to email redirection and unauthorized account activation
- Consider updating the Simple Membership plugin to a version beyond 4.8.3
- Monitor for suspicious account activation and email forwarding activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability details are based on information from the CVE Program and the National Vulnerability Database (NVD). The Simple Membership plugin's code and vulnerability reports from [email protected] provide additional context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97337 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97337
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97337 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97337
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-init-time-tasks.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-registration.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.