CVE-2026-14936

The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-06 22:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-14936

Mitre link : CVE-2026-14936

CVE.ORG link : CVE-2026-14936


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity