CVE-2026-88785
Simple Membership < 4.8.3 - Newly Registered Member Password Disclosure via URL Query String
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Simple Membership WordPress plugin before 4.8.3 does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration feature is enabled, exposing the credential in browser history and in web server, proxy, and CDN access logs to anyone able to read them.
| Vendor | unknown |
| Product | simple membership |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown simple membership
Be the first to know when new unknown vulnerabilities affecting unknown simple membership are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Simple Membership
0 < 4.8.3
References
Credits
Rafael Honorato WPScan