CVE-2026-97337
Received Received - Intake

Unauthenticated Email Redirection in Simple Membership Plugin

Vulnerability report for CVE-2026-97337, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: Wordfence

Description

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST['email'] parameter (overriding the member's registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member's activation email β€” and the follow-up 'registration complete' email containing the member's username and plaintext password β€” to an attacker-chosen address, and to then activate that member's account without their consent.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
simple_membership simple_membership to 4.8.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Simple Membership plugin for WordPress has a flaw in versions up to 4.8.3 where unauthenticated attackers can manipulate activation emails sent to pending members. The vulnerability occurs because the plugin's email activation endpoints lack authentication checks and use attacker-controlled input to override the recipient's email address. This allows attackers to redirect activation emails containing usernames and plaintext passwords to their own addresses.

Detection Guidance

Check for unauthorized activation emails or account modifications in WordPress logs. Inspect network traffic for POST requests to /wp-admin/admin-post.php with resend-activation or email-activation parameters. Look for unexpected changes in user accounts or email addresses.

Impact Analysis

If you use the affected plugin, an attacker could intercept your activation emails, gain access to your account credentials, and activate your account without your consent. This could lead to unauthorized access to your WordPress site or sensitive data associated with your account.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using the plugin may face compliance breaches, legal penalties, and reputational damage due to potential data exposure.

Mitigation Strategies

Update the Simple Membership plugin to the latest version. Disable the resend-activation and email-activation endpoints if possible. Implement strict input validation for email parameters in WordPress. Monitor user accounts for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97337. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart