CVE-2026-88764: Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard subsc_ref
The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Simple Membershipto a version that resolves this vulnerability.Fixed in 4.7.8
Event History
Frequently Asked Questions
Who can exploit this issue?
A member who can make a PayPal Standard payment can exploit the issue by supplying a membership level in the payment notification that differs from the level configured for the payment button. The vulnerable plugin may then grant a higher-privileged level while accepting payment for a lower-priced one.
Are sites affected by default?
The issue applies to Simple Membership versions before 4.7.8 when PayPal Standard payment notifications are used for membership purchases. The provided information does not establish whether PayPal Standard is enabled by default.
What should be checked for possible past exploitation?
Review PayPal Standard membership transactions for cases where the amount paid corresponds to a lower-priced membership level but the account was granted a more privileged level. Compare each member's granted level against the level configured for the payment button used for the transaction.