CVE-2026-15931: Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name
The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15931?
CVE-2026-15931 has a medium severity rating of 6.1 according to the CVSS 3.1 score.
How do I fix CVE-2026-15931?
To fix CVE-2026-15931, update the Simple Membership plugin to version 4.7.8 or later.
What type of vulnerability is CVE-2026-15931?
CVE-2026-15931 is classified as an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-15931?
Users of the Simple Membership WordPress plugin before version 4.7.8 are affected by CVE-2026-15931.
What can an attacker do with CVE-2026-15931?
An attacker can exploit CVE-2026-15931 to store arbitrary JavaScript that executes in the administration dashboard.