CVE-2026-15930

Simple Membership · Simple Membership WordPress plugin

The Simple Membership WordPress plugin contains an authorization bypass vulnerability allowing unauthenticated attackers to overwrite administrator account data and perform account takeovers.

Executive summary

An unauthenticated vulnerability in the Simple Membership WordPress plugin allows attackers to overwrite administrator account data, posing a critical risk of full site compromise.

Vulnerability

The plugin fails to verify user creation status during registration, enabling an unauthenticated attacker to manipulate the user ID parameter. This allows the attacker to overwrite existing administrator profile details, including email addresses, to facilitate a password reset and gain unauthorized administrative access.

Business impact

Successful exploitation results in total loss of administrative control over the affected WordPress instance. This leads to unauthorized data access, potential distribution of malicious content, and complete system compromise, justifying the critical 9.4 CVSS score.

Remediation

Immediate Action: Update the Simple Membership plugin to version 4.7.8 or later immediately.

Proactive Monitoring: Review user registration logs for anomalous activity, specifically looking for new administrator accounts or unexpected modifications to existing administrative email addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious registration requests that do not follow standard plugin workflows.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a critical security failure that can be exploited by any remote attacker without authentication. Administrators must prioritize updating the Simple Membership plugin to version 4.7.8 immediately to prevent total account takeover and site compromise.