Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Simple Membership — Vulnerabilities & Security Advisories 30

All 30 CVE vulnerabilities found in Simple Membership, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security weaknesses associated with the Simple Membership software product, focusing on common vulnerability classifications such as injection flaws and cross-site scripting. The content compiles historical vulnerability records and vendor advisories spanning from the initial release of the software through to the most recent documented incidents, providing a comprehensive timeline of security issues. Here, users can track a specific vendor's security advisories to understand their response patterns, gain a deeper understanding of specific weakness classes by examining their prevalence and impact within this product ecosystem, and look up the complete vulnerability history of Simple Membership to assess long-term risk exposure. By centralizing these disparate data points, the page serves as a vital resource for security analysts, developers, and administrators who need to evaluate the attack surface of this membership management tool. It allows for a granular view of how different types of exploits have affected the product over time, highlighting trends in code quality and security practices. This structured approach facilitates better decision-making regarding patching priorities, mitigation strategies, and architectural improvements, ensuring that stakeholders have access to a clear and organized repository of security intelligence without the noise of unrelated data.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-88764 Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref - - 2026-09-13
CVE-2026-77194 Simple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity Binding CWE-287 5.3 Medium 2026-09-01
CVE-2026-14936 Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification 5.3 Medium 2026-08-06
CVE-2026-66712 WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerability CWE-862 7.5 High 2026-08-06
CVE-2026-15931 Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name - - 2026-08-03
CVE-2026-15930 Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision - - 2026-08-03
CVE-2026-11855 Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version - - 2026-07-06
CVE-2026-12093 Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook CWE-862 5.3 Medium 2026-06-18
CVE-2026-42663 WordPress Simple Membership plugin <= 4.7.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-06-15
CVE-2026-34886 WordPress Simple Membership plugin <= 4.7.1 - Broken Access Control vulnerability CWE-862 7.5 High 2026-06-15
CVE-2026-1461 Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values CWE-230 6.5 Medium 2026-02-19
CVE-2026-25308 WordPress Simple Membership plugin <= 4.6.9 - Broken Access Control vulnerability CWE-862 4.3 Medium 2026-02-19
CVE-2025-49333 WordPress Simple Membership plugin <= 4.6.3 - Cross Site Scripting (XSS) Vulnerability CWE-79 5.9 Medium 2025-06-06
CVE-2024-11088 Simple Membership <= 4.5.5 - Exposure of Private Personal Information to an Unauthorized Actor CWE-200 5.3 Medium 2024-11-21
CVE-2024-49682 WordPress Simple Membership plugin <= 4.5.3 - Open Redirection vulnerability CWE-601 4.7 Medium 2024-10-24
CVE-2023-41957 WordPress Simple Membership plugin <= 4.3.4 - Unauthenticated Membership Role Privilege Escalation vulnerability CWE-269 8.6 High 2024-05-17
CVE-2023-41956 WordPress Simple Membership plugin <= 4.3.4 - Authenticated Account Takeover vulnerability CWE-287 8.8 High 2024-05-17
CVE-2024-4383 Simple Membership <= 4.4.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium 2024-05-09
CVE-2024-3730 Simple Membership <= 4.4.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 5.4 Medium 2024-04-25
CVE-2024-1985 Simple Membership <= 4.4.2 - Unauthenticated Stored Self-Based Cross-Site Scripting CWE-79 4.7 Medium 2024-03-13
CVE-2024-22308 WordPress Simple Membership Plugin <= 4.4.1 is vulnerable to Open Redirection CWE-601 3.4 Low 2024-01-24
CVE-2023-6882 Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting Vulnerability via environment_mode CWE-79 6.1 Medium 2024-01-11
CVE-2023-50376 WordPress Simple Membership Plugin <= 4.3.8 is vulnerable to Unauth. Reflected Cross Site Scripting (XSS) CWE-79 7.1 High 2023-12-19
CVE-2023-4719 Simple Membership <= 4.3.5 - Reflected Cross-Site Scripting CWE-79 7.2 High 2023-09-06
CVE-2022-4469 Simple Membership < 4.2.2 - Contributor+ Stored XSS 5.4 - 2023-01-16
CVE-2022-2317 Simple Membership < 4.1.3 - Unauthenticated Membership Privilege Escalation CWE-269 8.8 - 2022-08-01
CVE-2022-2273 Simple Membership < 4.1.3 - Membership Privilege Escalation CWE-269 8.8 - 2022-08-01
CVE-2022-1724 Simple Membership < 4.1.1 - Reflected Cross-Site Scripting CWE-79 6.1 - 2022-06-13
CVE-2022-0681 Simple Membership < 4.1.0 - Arbitrary Transaction Deletion via CSRF CWE-352 6.5 - 2022-03-21
CVE-2022-0328 Simple Membership < 4.0.9 - Arbitrary Member Deletion via CSRF CWE-352 4.3 - 2022-02-28

All 30 known CVE vulnerabilities affecting Simple Membership with full Chinese analysis, references, and POCs where available.