WordPress Plugin Vulnerabilities

Simple Membership < 4.8.3 - Newly Registered Member Password Disclosure via URL Query String

Description

The plugin does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration feature is enabled, exposing the credential in browser history and in web server, proxy, and CDN access logs to anyone able to read them.

Proof of Concept

Affects Plugins

Fixed in 4.8.3

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Rafael Honorato
Submitter
Rafael Honorato
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-09 (about 2 days ago)
Added
2026-10-09 (about 1 day ago)
Last Updated
2026-10-09 (about 1 day ago)

Other