CVE-2026-1461
Awaiting Analysis Awaiting Analysis - Queue
Improper Validation in Simple Membership Plugin Enables Unauthorized Subscription Manipulation

Publication date: 2026-02-19

Last updated on: 2026-02-19

Assigner: Wordfence

Description
The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is due to the plugin only validating webhook signatures when the stripe-webhook-signing-secret setting is configured, which is empty by default. This makes it possible for unauthenticated attackers to forge Stripe webhook events to manipulate membership subscriptions, including reactivating expired memberships without payment or canceling legitimate subscriptions, potentially leading to unauthorized access and service disruption.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-19
Last Modified
2026-02-19
Generated
2026-06-16
AI Q&A
2026-02-19
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
simple_membership plugin to 4.7.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-230 The product does not handle or incorrectly handles when a parameter, field, or argument name is specified, but the associated value is missing, i.e. it is empty, blank, or null.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The Simple Membership plugin for WordPress has a vulnerability in versions up to and including 4.7.0 related to improper handling of missing values in its Stripe webhook handler.

Specifically, the plugin only validates webhook signatures if the stripe-webhook-signing-secret setting is configured, but this setting is empty by default.

Because of this, unauthenticated attackers can forge Stripe webhook events, allowing them to manipulate membership subscriptions.

  • They can reactivate expired memberships without payment.
  • They can cancel legitimate subscriptions.

This can lead to unauthorized access and disruption of services.

Impact Analysis

This vulnerability can have several impacts on users of the Simple Membership plugin:

  • Unauthorized access to membership content by reactivating expired memberships without payment.
  • Disruption of legitimate services by canceling valid subscriptions.

Overall, it can lead to financial loss and service reliability issues.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1461. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart