CVE-2026-88785
Received Received - Intake

Simple Membership WordPress Plugin Password Exposure

Vulnerability report for CVE-2026-88785, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Simple Membership WordPress plugin before 4.8.3 does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration feature is enabled, exposing the credential in browser history and in web server, proxy, and CDN access logs to anyone able to read them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Simple Membership 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Simple Membership WordPress plugin before version 4.8.3. When the auto-login-after-registration feature is enabled, the plugin transmits a newly registered member's plaintext password in a URL query string. This exposes the password in browser history and server logs, including web servers, proxies, and CDNs.

Detection Guidance

Check WordPress plugin versions for Simple Membership. If using version before 4.8.3, the vulnerability may exist. Inspect web server, proxy, and CDN access logs for URLs containing plaintext passwords in query strings during registration.

Impact Analysis

If you use the affected plugin version, attackers with access to logs or browser history could steal plaintext passwords. This may lead to unauthorized account access, data breaches, or further exploitation of user accounts.

Compliance Impact

This vulnerability could violate GDPR and HIPAA requirements for protecting sensitive data. Exposure of plaintext passwords may result in unauthorized access to personal or health information, leading to compliance violations and potential legal penalties.

Mitigation Strategies

Update the Simple Membership plugin to version 4.8.3 or later immediately. Disable the auto-login-after-registration feature if not required. Review and sanitize access logs for any exposed credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88785. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart