AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-11855

HIGH · CVSS 8.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

The Simple Membership WordPress plugin prior to version 4.7.5 is vulnerable due to inadequate verification of Stripe webhook requests and improper output handling, which can lead to arbitrary web script injection. This vulnerability allows unauthenticated attackers to execute malicious scripts in the context of a logged-in administrator, potentially compromising the site. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-11855
Severity
HIGH
CVSS
8.8
EPSS
0.28%
WordPress

Original NVD Description

The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in the context of a logged-in administrator.