๐Ÿ” CVE Alert

CVE-2026-88764

MEDIUM 5.4

Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.

Vendor unknown
Product simple membership
Published Sep 13, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for unknown simple membership

Be the first to know when new medium vulnerabilities affecting unknown simple membership are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Simple Membership
0 < 4.7.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/54fdf46e-0385-40a3-b3bc-a862dc0fb03e/

Credits

Charles Vosburgh WPScan