CVE

CVE-2026-15931 — Simple Membership [simple-membership] < 4.7.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15931 Simple Membership [simple-membership] < 4.7.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 4.7.8 4.7.8 2026-07-24

CVE-2026-15931

A vulnerability exists in versions of the Simple Membership WordPress plugin prior to 4.7.8, where a malicious actor can inject and execute arbitrary JavaScript code within an admin's session by submitting a specially crafted payment approval request without authentication. This is due to inadequate input validation and output escaping mechanisms in the affected plugin version. As a result, unauthenticated attackers can potentially manipulate the administrator's dashboard with malicious scripts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.