CVE Database /
CVE-2026-14936
CVE · Medium
CVE-2026-14936 — Simple Membership [simple-membership] < 4.7.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-14936
|
Simple Membership [simple-membership] < 4.7.7 |
Insufficient Verification of Data Authenticity |
Medium
5.3
|
< 4.7.7
|
4.7.7 |
2026-08-06 |
—
|
CVE-2026-14936
A vulnerability in the Simple Membership WordPress plugin prior to version 4.7.7 allows unauthorized individuals to initiate or prolong memberships by exploiting a flaw related to PayPal transaction verification. Specifically, the plugin fails to confirm that incoming payments were directed to its own merchant account before granting membership access. This oversight enables malicious users to manipulate membership status using external payment sources.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings