CVE-2026-103067: WordPress Memberful - Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
memberful-wpto a version that resolves this vulnerability.Fixed in 1.81.1
Event History
Frequently Asked Questions
What access and interaction are required to exploit this issue?
The vulnerability is network-accessible and has low attack complexity, but exploitation requires low-privileged access and user interaction. The available data does not identify which authenticated role or action is involved.
Which plugin versions are affected?
Memberful - Membership Plugin versions through 1.81.0 are affected. The data does not provide a fixed version or workaround.
What is the potential impact of a successful exploit?
The reported CVSS vector rates confidentiality, integrity, and availability impact as high. A successful CSRF attack could cause actions to be performed in the context of an affected user, subject to that user's available permissions.