CVE-2026-104401: WordPress Memberful - Membership Plugin plugin <= 1.81.2 - Sensitive Data Exposure vulnerability
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/memberful-wpto a version that resolves this vulnerability.Fixed in 1.82.0
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges (PR:L). It can be exploited remotely without user interaction, as indicated by the AV:N and UI:N metrics.
What information could be exposed?
The issue is described as allowing retrieval of embedded sensitive data and has a confidentiality impact of low (C:L). The available data does not identify the specific data elements that may be disclosed.
Which plugin versions are affected?
Memberful - Membership Plugin versions through 1.81.2 are affected. The lower bound is listed as n/a, so the available data does not establish the first vulnerable release.