CVE-2026-15930 PUBLISHED

Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision

Assigner: WPScan
Reserved: 16.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.

Product Status

Vendor Unknown
Product Simple Membership
Versions Default: unaffected
  • affected from 0 to 4.7.8 (excl.)

Credits

  • Brandon Steed finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE