{"id":"CVE-2026-97337","title":"The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints","summary":"The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endp…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-862"],"vendor":"wpinsider-1","product":"Simple Membership","affected":["simple_membership <= 4.8.3"],"published":"2026-10-03","updated":"2026-10-03","sourceUpdated":"2026-10-03T06:16:48.943","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97337","references":[{"url":"https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php#L774","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php#L850","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-init-time-tasks.php#L167","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-registration.php#L75","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3716437%40simple-membership&new=3716437%40simple-membership","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/ae2b6c4c-7dd6-41e7-8b8d-c09aa7fa660b?source=cve","label":"security@wordfence.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-03T06:39:57.570Z","slug":"CVE-2026-97337","body":"## Overview\n\nThe Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST['email'] parameter (overriding the member's registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member's activation email — and the follow-up 'registration complete' email containing the member's username and plaintext password — to an attacker-chosen address, and to then activate that member's account without their consent.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}