WordPress Plugin Vulnerabilities

Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification

Description

The plugin does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control.

Proof of Concept

Affects Plugins

Fixed in 4.7.7

References

Miscellaneous

Original Researcher
Muni Nitish Kumar Yaddala
Submitter
Muni Nitish Kumar Yaddala
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 26 days ago)
Added
2026-07-13 (about 25 days ago)
Last Updated
2026-07-13 (about 25 days ago)

Other