AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14936

MEDIUM · CVSS 5.3 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Simple Membership WordPress plugin prior to version 4.7.7 is vulnerable as it fails to verify PayPal payment notifications against the site's configured merchant account. This flaw allows unauthenticated users to activate or extend memberships by exploiting payments made to any PayPal account they control. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized membership activations.

CVE
CVE-2026-14936
Severity
MEDIUM
CVSS
5.3
EPSS
0.16%
WordPress

Original NVD Description

The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control.