OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103067

HIGH · CVSS 8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A Cross-Site Request Forgery (CSRF) vulnerability in the Memberful Membership Plugin for WordPress allows attackers to perform unauthorized actions on behalf of authenticated users. This could lead to unauthorized access or manipulation of user accounts, potentially compromising sensitive information. Users of the Memberful plugin, particularly those running versions up to 1.81.0, should prioritize applying security updates to mitigate this risk.

CVE
CVE-2026-103067
Severity
HIGH
CVSS
8
EPSS
0.12%

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0.