---
id: CVE-2026-97337
title: >-
  The Simple Membership plugin for WordPress is vulnerable to unauthorized
  modification of data and sensitive information disclosure in versions up to,
  and including, 4.8.3 via the resend-activation and email-activation endpoints
summary: >-
  The Simple Membership plugin for WordPress is vulnerable to unauthorized
  modification of data and sensitive information disclosure in versions up to,
  and including, 4.8.3 via the resend-activation and email-activation endpoints.
  The endp…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
vendor: wpinsider-1
product: Simple Membership
affected:
  - simple_membership <= 4.8.3
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:48.943'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97337'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php#L774
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php#L850
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-init-time-tasks.php#L167
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-registration.php#L75
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3716437%40simple-membership&new=3716437%40simple-membership
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/ae2b6c4c-7dd6-41e7-8b8d-c09aa7fa660b?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.570Z'
---

## Overview

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST['email'] parameter (overriding the member's registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member's activation email — and the follow-up 'registration complete' email containing the member's username and plaintext password — to an attacker-chosen address, and to then activate that member's account without their consent.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
