WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Simple Membership?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Simple Membership — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: simple-membership
  • 40000+ instalaciones activas

membermembersmembers-onlymembershipmemberships

Estado de mantenimiento

  • Última versión conocida: 4.7.8
  • Requiere PHP: 7.4+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

29 CVEs conocidos registrados para Simple Membership.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-11855 Simple Membership [simple-membership] < 4.7.5 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 4.7.5 4.7.5 2026-07-06 ✓ corregido en la última versión
CVE-2026-12093 Simple Membership [simple-membership] < 4.7.6 Falta de control de autorización Media 5,3 < 4.7.6 4.7.6 2026-06-17 ✓ corregido en la última versión
CVE-2026-42663 Simple Membership [simple-membership] < 4.7.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,5 < 4.7.3 4.7.3 2026-05-03 ✓ corregido en la última versión
CVE-2026-34886 Simple Membership [simple-membership] < 4.7.2 Falta de control de autorización Alta 7,5 < 4.7.2 4.7.2 2026-03-31 ✓ corregido en la última versión
CVE-2026-25308 Simple Membership [simple-membership] < 4.7.0 Falta de control de autorización Media 4,3 < 4.7.0 4.7.0 2026-01-19 ✓ corregido en la última versión
CVE-2025-49333 Simple Membership [simple-membership] < 4.6.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,9 < 4.6.4 4.6.4 2025-06-05 ✓ corregido en la última versión
CVE-2024-11088 Simple Membership [simple-membership] < 4.5.6 Exposición de información sensible a un actor no autorizado Media 5,3 < 4.5.6 4.5.6 2024-11-20 ✓ corregido en la última versión
CVE-2024-49682 Simple Membership [simple-membership] < 4.5.4 Redirección de URL a un sitio no confiable (Open Redirect) Media 4,7 < 4.5.4 4.5.4 2024-10-21 ✓ corregido en la última versión

CVE-2026-11855

The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in the context of a logged-in administrator.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-12093

The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by forging a charge.refunded webhook event containing a victim's subscription ID, setting the target member's account_state to 'inactive' and triggering cancellation hooks, transaction-record status changes, and cancellation notification emails. This vulnerability is exploitable only on installations where no Stripe webhook signing secret has been configured, which is the default out-of-the-box state; sites that have configured the stripe-webhook-signing-secret option are routed to the properly verified HMAC path and are not affected.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-42663

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-34886

The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.7.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-25308

The Simple Membership plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.6.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-49333

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.6.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-11088

The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-49682

The Simple Membership plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 4.5.3. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

+ 26 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-4383 Simple Membership [simple-membership] < 4.4.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 4.4.6 4.4.6 2024-05-03 ✓ corregido en la última versión
CVE-2024-3730 Simple Membership [simple-membership] < 4.4.4 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 4.4.4 4.4.4 2024-04-24 ✓ corregido en la última versión
CVE-2024-1985 Simple Membership [simple-membership] < 4.4.3 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.4.3 4.4.3 2024-03-05 ✓ corregido en la última versión
CVE-2024-22308 Simple Membership [simple-membership] < 4.4.2 Redirección de URL a un sitio no confiable (Open Redirect) Baja 3,4 < 4.4.2 4.4.2 2024-01-19 ✓ corregido en la última versión
CVE-2023-50376 Simple Membership [simple-membership] < 4.3.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 4.3.9 4.3.9 2023-12-19 ✓ corregido en la última versión
CVE-2023-6882 Simple Membership [simple-membership] < 4.3.9 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.3.9 4.3.9 2023-12-18 ✓ corregido en la última versión
CVE-2023-41956 Simple Membership [simple-membership] < 4.3.5 Autenticación indebida Alta 8,8 < 4.3.5 4.3.5 2023-09-25 ✓ corregido en la última versión
CVE-2023-41957 Simple Membership [simple-membership] < 4.3.5 Gestión incorrecta de privilegios Alta 8,6 < 4.3.5 4.3.5 2023-09-25 ✓ corregido en la última versión
CVE-2023-4719 Simple Membership [simple-membership] < 4.3.6 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.3.6 4.3.6 2023-09-05 ✓ corregido en la última versión
CVE-2022-4469 Simple Membership [simple-membership] < 4.2.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 4.2.2 4.2.2 2022-12-21 ✓ corregido en la última versión
CVE-2022-2273 Simple Membership [simple-membership] < 4.1.3 Gestión incorrecta de privilegios Alta 8,8 < 4.1.3 4.1.3 2022-07-06 ✓ corregido en la última versión
CVE-2022-2317 Simple Membership [simple-membership] < 4.1.3 Gestión incorrecta de privilegios Crítica 9,8 < 4.1.3 4.1.3 2022-07-06 ✓ corregido en la última versión
CVE-2022-1724 Simple Membership [simple-membership] < 4.1.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 4.1.1 4.1.1 2022-05-23 ✓ corregido en la última versión
CVE-2022-0681 Simple Membership [simple-membership] < 4.1.0 Falsificación de petición en sitios cruzados (CSRF) Media 6,5 < 4.1.0 4.1.0 2022-02-25 ✓ corregido en la última versión
CVE-2022-0328 Simple Membership [simple-membership] < 4.0.9 Falsificación de petición en sitios cruzados (CSRF) Media 4,7 < 4.0.9 4.0.9 2022-01-25 ✓ corregido en la última versión
Simple Membership [simple-membership] < 4.0.4 Desconocido < 4.0.4 4.0.4 2021-04-05 ✓ corregido en la última versión
CVE-2019-14328 Simple Membership [simple-membership] < 3.8.5 Falsificación de petición en sitios cruzados (CSRF) Alta 8,8 < 3.8.5 3.8.5 2019-07-27 ✓ corregido en la última versión
CVE-2017-18499 Simple Membership [simple-membership] < 3.5.7 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 3.5.7 3.5.7 2017-11-08 ✓ corregido en la última versión
CVE-2016-10884 Simple Membership [simple-membership] < 3.3.3 Falsificación de petición en sitios cruzados (CSRF) Alta 8,8 < 3.3.3 3.3.3 2016-09-16 ✓ corregido en la última versión
Simple Membership [simple-membership] < 3.2.9 Desconocido < 3.2.9 3.2.9 2016-07-14 ✓ corregido en la última versión
Simple Membership [simple-membership] < 3.2.9 Desconocido < 3.2.9 3.2.9 2016-07-14 ✓ corregido en la última versión
CVE-2021-29232 Simple Membership [simple-membership] < 4.0.4 Desconocido < 4.0.4 4.0.4 0000-00-00 ✓ corregido en la última versión
CVE-2026-1461 Simple Membership [simple-membership] < 4.7.1 Desconocido < 4.7.1 4.7.1 0000-00-00 ✓ corregido en la última versión
Simple Membership [simple-membership] < 3.2.9 Desconocido < 3.2.9 3.2.9 ✓ corregido en la última versión
Simple Membership <= 3.2.8 - Cross-Site Scripting (XSS) Desconocido < 3.2.9 3.2.9 ✓ corregido en la última versión
CVE-2026-14936 Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification Desconocido < 4.7.7 4.7.7 ✓ corregido en la última versión

CVE-2024-4383

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3730

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_subscription_cancel_link' shortcode in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-1985

The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-22308

Update the WordPress Simple Membership plugin to the latest available version (at least 4.4.2). Joshua Chan discovered and reported this Open Redirection vulnerability in WordPress Simple Membership Plugin. This could allow a malicious actor to redirect users from one site to the other due to the redirect URL not being validated. Users could be tricked to visiting a legitimate site to then be redirected to a malicious site and cause a phishing incident. This vulnerability has been fixed in version 4.4.2. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-50376

Update the WordPress Simple Membership plugin to the latest available version (at least 4.3.9). Le Ngoc Anh discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Membership Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 4.3.9. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6882

The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environment_mode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-41956

Update the WordPress Simple Membership plugin to the latest available version (at least 4.3.5). Rafie Muhammad (Patchstack) discovered and reported this Privilege Escalation vulnerability in WordPress Simple Membership Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website if high privileges are gained. This vulnerability has been fixed in version 4.3.5.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-41957

Update the WordPress Simple Membership plugin to the latest available version (at least 4.3.5). Rafie Muhammad (Patchstack) discovered and reported this Privilege Escalation vulnerability in WordPress Simple Membership Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website if high privileges are gained. This vulnerability has been fixed in version 4.3.5.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-4719

Update the WordPress Simple Membership plugin to the latest available version (at least 4.3.6). FearZzZz discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Membership Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 4.3.6.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-4469

Update the WordPress Simple Membership plugin to the latest available version (at least 4.2.2). Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Simple Membership Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 4.2.2.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-2273

The Simple Membership plugin for WordPress is vulnerable to membership related privilege escalation in versions up to, and including, 4.1.2. This is due to insufficient validation on the membership membership_level supplied which makes it possible for authenticated users to supplied arbitrary membership levels and be granted to permissions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-2317

The Simple Membership plugin for WordPress is vulnerable to membership related privilege escalation in versions up to, and including, 4.1.2. This is due to insufficient validation on the membership level_identifier supplied which makes it possible for unauthenticated users to supplied arbitrary membership levels and be granted to permissions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-1724

Reflected Cross-Site Scripting (XSS) vulnerability discovered by cydave in WordPress Simple Membership plugin (versions <= 4.1.0). Update the WordPress Simple Membership plugin to the latest available version (at least 4.1.1).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-0681

The Simple Membership WordPress plugin before 4.1.0 does not have Cross-Site Request Forgery (CSRF) protections in place when deleting Transactions, which could allow attackers to make a logged in admin delete arbitrary transactions via a CSRF attack

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-0328

The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

Simple Membership [simple-membership] < 4.0.4

The Simple Membership plugin for WordPress is vulnerable to time-based SQL Injection via the 's' and 'status' parameters in versions up to, and including, 4.0.3 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated Admin+ attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2019-14328

Cross-Site Request Forgery (CSRF) vulnerability found by rubyman in WordPress Simple Membership plugin (versions <= 3.8.4).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2017-18499

The Simple Membership plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2016-10884

The Simple Membership plugin for WordPress is vulnerable to multiple Cross-Site Request Forgery attacks in versions up to, and including, 3.3.2. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain administrative access and perform otherwise restricted actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Simple Membership [simple-membership] < 3.2.9

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Simple Membership [simple-membership] < 3.2.9

The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in versions before 3.2.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-29232

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-1461

The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, and including, 4.7.0 via the Stripe webhook handler. This is due to the plugin only validating webhook signatures when the stripe-webhook-signing-secret setting is configured, which is empty by default. This makes it possible for unauthenticated attackers to forge Stripe webhook events to manipulate membership subscriptions, including reactivating expired memberships without payment or canceling legitimate subscriptions, potentially leading to unauthorized access and service disruption.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Simple Membership [simple-membership] < 3.2.9

The Simple Membership WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Simple Membership actualizado — 4.7.8 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.