CVE · Medium

CVE-2026-12093 — Simple Membership [simple-membership] < 4.7.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12093 Simple Membership [simple-membership] < 4.7.6 Missing Authorization Medium 5.3 < 4.7.6 4.7.6 2026-06-17

CVE-2026-12093

The Simple Membership plugin for WordPress has a security flaw that allows unauthorized users to deactivate any account, without needing to log in. This happens because the plugin doesn't properly check if a user is allowed to take certain actions, making it possible for attackers to trick the system into deactivating an account by sending a fake notification. This vulnerability can only be exploited if the website doesn't have a secret key set up to verify incoming notifications, which is the default setting.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.