---
id: CVE-2026-88785
title: >-
  The Simple Membership WordPress plugin before 4.8.3 does not avoid
  transmitting a newly registered member's plaintext password in a URL query
  string when an optional auto-login-after-registration feature is enabled,
  exposing the credenti…
summary: >-
  The Simple Membership WordPress plugin before 4.8.3 does not avoid
  transmitting a newly registered member's plaintext password in a URL query
  string when an optional auto-login-after-registration feature is enabled,
  exposing the credenti…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
published: '2026-10-11'
updated: '2026-10-11'
sourceUpdated: '2026-10-11T12:17:25.547'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88785'
references:
  - url: 'https://wpscan.com/vulnerability/7d9a6fe5-fcfc-48f0-a811-8623a69422df/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-10-11T08:44:24.723Z'
---

## Overview

The Simple Membership WordPress plugin before 4.8.3 does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration feature is enabled, exposing the credential in browser history and in web server, proxy, and CDN access logs to anyone able to read them.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
