CVE-2026-66712: WordPress Simple Membership plugin <= 4.7.8 - Broken Access Control vulnerability
Published Aug 6, 2026
·Updated
Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.
Affected Software
1 affected component
WordPress Simple Membership<=4.7.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Simple Membership pluginto a version that resolves this vulnerability.Fixed in 4.7.9
Event History
Aug 6, 2026
CVE Published
via MITRE·02:27 PM
Data Sourced
via MITRE·02:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66712?
CVE-2026-66712 is rated with a high severity score of 7.5.
2
What type of vulnerability is CVE-2026-66712?
CVE-2026-66712 is a Broken Access Control vulnerability affecting versions of the Simple Membership plugin up to 4.7.8.
3
How do I fix CVE-2026-66712?
To fix CVE-2026-66712, upgrade the WordPress Simple Membership plugin to version 4.7.9 or later.
4
What impact does CVE-2026-66712 have on my website?
CVE-2026-66712 can allow unauthenticated users to exploit access control issues, leading to potential unauthorized actions.
5
Who is affected by CVE-2026-66712?
All users of the Simple Membership plugin versions 4.7.8 and below are at risk from CVE-2026-66712.