CVE-2026-11855
The Simple Membership plugin for WordPress prior to version 4.7.5 fails to authenticate Stripe webhook notifications when no signing key is set up, and also neglects to sanitize data from these notifications before displaying it in an admin notice, creating a vulnerability that can be exploited by unauthorized parties to inject malicious code that runs with the privileges of a logged-in administrator. This allows attackers to bypass authentication checks and execute arbitrary web scripts on the affected site.
Based on public CVE data (MITRE/NVD).