Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77194— Simple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity Binding

Quick assessment

Affected
wpinsider-1 Simple Membership
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Simple Membership 插件在 4.8.0 及更早的版本中,存在身份验证缺失(Authentication Bypass)导致的管理员账户接管(Administrator Account Takeover)漏洞。该漏洞源于在 WordPress Multisite(多站点)环境中,插件在公开注册流程中未进行适当的身验证:它仅凭匹配的用户名和邮箱,将新的 Simple Membership 记录绑定到现有的全局 WordPress 用户,既未要求密码验证或所有权证明,也未能正确检测

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77194

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Simple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity Binding
Source: CVE Program / CVE List V5
Vulnerability Description
The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is due to improper identity verification during the public registration flow in WordPress Multisite environments, where the plugin binds new Simple Membership records to existing global WordPress users based solely on matching username and email, without requiring password verification or ownership proof, and fails to properly detect Administrator roles on child sites. This makes it possible for unauthenticated attackers to take over Administrator accounts on child sites in a Multisite network by registering a Simple Membership account with a victim's credentials on a site where public registration is enabled, then updating the victim's global WordPress password through the profile edit functionality. The vulnerability was partially patched in version 4.8.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wpinsider-1 Simple Membership 0 ~ 4.8.1 -

II. Public POCs for CVE-2026-77194

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77194

登录查看更多情报信息。

Patches & Fixes for CVE-2026-77194 (1)

Vendor Pages for CVE-2026-77194 (1)

Other References for CVE-2026-77194 (2)

Other References for CVE-2026-77194 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77194

No comments yet


Leave a comment