WordPress Plugin Vulnerabilities
Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification
Description
The plugin does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Muni Nitish Kumar Yaddala
Submitter
Muni Nitish Kumar Yaddala
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-13 (about 26 days ago)
Added
2026-07-13 (about 25 days ago)
Last Updated
2026-07-13 (about 25 days ago)