WordPress Plugin Vulnerabilities

Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision

Description

The plugin does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.

Proof of Concept

Affects Plugins

Fixed in 4.7.8

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Brandon Steed
Submitter
Brandon Steed
Verified
Yes

Timeline

Publicly Published
2026-07-24 (about 10 days ago)
Added
2026-07-24 (about 9 days ago)
Last Updated
2026-07-31 (about 2 days ago)

Other