CVE-2026-12093
The Simple Membership plugin for WordPress has a security flaw that allows unauthorized users to deactivate any account, without needing to log in. This happens because the plugin doesn't properly check if a user is allowed to take certain actions, making it possible for attackers to trick the system into deactivating an account by sending a fake notification. This vulnerability can only be exploited if the website doesn't have a secret key set up to verify incoming notifications, which is the default setting.
Based on public CVE data (MITRE/NVD).