CVE-2026-15931
A vulnerability exists in versions of the Simple Membership WordPress plugin prior to 4.7.8, where a malicious actor can inject and execute arbitrary JavaScript code within an admin's session by submitting a specially crafted payment approval request without authentication. This is due to inadequate input validation and output escaping mechanisms in the affected plugin version. As a result, unauthenticated attackers can potentially manipulate the administrator's dashboard with malicious scripts.
Based on public CVE data (MITRE/NVD).