CVE-2026-97337
Description
The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST['email'] parameter (overriding the member's registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member's activation email — and the follow-up 'registration complete' email containing the member's username and plaintext password — to an attacker-chosen address, and to then activate that member's account without their consent.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php#L774
- https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-front-registration.php#L850
- https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-init-time-tasks.php#L167
- https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.8.3/classes/class.swpm-registration.php#L75
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3716437%40simple-membership&new=3716437%40simple-membership
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ae2b6c4c-7dd6-41e7-8b8d-c09aa7fa660b?source=cve
CWEs
CWE-862
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.