Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-12093— Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook

CVSS 5.3 · Medium EPSS 0.35% · P28

Possible ATT&CK Techniques 1AI

T1133 · External Remote Services

Affected Version Matrix 1

VendorProductVersion RangeStatus
wpinsider-1Simple Membership≤ 4.7.5affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-12093

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook
Source: CVE Program / CVE List V5
Vulnerability Description
The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by forging a charge.refunded webhook event containing a victim's subscription ID, setting the target member's account_state to 'inactive' and triggering cancellation hooks, transaction-record status changes, and cancellation notification emails. This vulnerability is exploitable only on installations where no Stripe webhook signing secret has been configured, which is the default out-of-the-box state; sites that have configured the stripe-webhook-signing-secret option are routed to the properly verified HMAC path and are not affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
Wpinsider-1 Simple Membership 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Wpinsider-1 Simple Membership是Wpinsider-1公司的一款专注于用户注册与访问管理的 WordPress 插件,主要用途是为网站添加会员功能,支持用户注册、登录、内容访问限制等典型操作。 Wpinsider-1 Simple Membership 4.7.5及之前版本存在授权问题漏洞,该漏洞源于未正确验证用户授权,可能导致未经身份验证的攻击者通过伪造包含受害者订阅ID的charge.refunded webhook事件,将目标成员账户状态设置为非活动,从而停用任意成员账户
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
wpinsider-1Simple Membership 0 ~ 4.7.5 -

II. Public POCs for CVE-2026-12093

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12093

登录查看更多情报信息。

Patches & Fixes for CVE-2026-12093 (1)

Vendor Advisories for CVE-2026-12093 (1)

Vendor Pages for CVE-2026-12093 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-12093

No comments yet


Leave a comment