CVE-2026-88764
Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.
| Vendor | unknown |
| Product | simple membership |
| Published | Sep 13, 2026 |
| Last Updated | Sep 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown simple membership
Be the first to know when new medium vulnerabilities affecting unknown simple membership are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Simple Membership
0 < 4.7.8
References
Credits
Charles Vosburgh WPScan