CVE-2026-15931 PUBLISHED

Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name

Assigner: WPScan
Reserved: 16.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's session.

Product Status

Vendor Unknown
Product Simple Membership
Versions Default: unaffected
  • affected from 0 to 4.7.8 (excl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE