CVE-2026-14936: Simple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Simple Membershipto a version that resolves this vulnerability.Fixed in 4.7.7 - Configuration
Ensure the plugin verifies that a PayPal IPN notification was sent to the site's own configured merchant account before activating or extending memberships (problem described for plugin versions before 4.7.7).
Simple Membership WordPress plugin PayPal IPN receiver verification = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14936?
The severity of CVE-2026-14936 is classified as medium with a score of 5.3.
How do I fix CVE-2026-14936?
To fix CVE-2026-14936, upgrade the Simple Membership plugin to version 4.7.7 or later.
What type of vulnerability is CVE-2026-14936?
CVE-2026-14936 is a vulnerability that allows unauthenticated users to bypass payment verification for membership activation.
What systems are affected by CVE-2026-14936?
CVE-2026-14936 affects WordPress sites using the Simple Membership plugin before version 4.7.7.
What is the impact of CVE-2026-14936?
The impact of CVE-2026-14936 allows unauthorized users to activate or extend memberships without proper payment verification.