CVE

CVE-2026-11855 — Simple Membership [simple-membership] < 4.7.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-11855 Simple Membership [simple-membership] < 4.7.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 4.7.5 4.7.5 2026-07-06

CVE-2026-11855

The Simple Membership plugin for WordPress prior to version 4.7.5 fails to authenticate Stripe webhook notifications when no signing key is set up, and also neglects to sanitize data from these notifications before displaying it in an admin notice, creating a vulnerability that can be exploited by unauthorized parties to inject malicious code that runs with the privileges of a logged-in administrator. This allows attackers to bypass authentication checks and execute arbitrary web scripts on the affected site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.