CyberRota Analysis
AI-GeneratedThe Simple Membership WordPress plugin prior to version 4.7.7 is vulnerable as it fails to verify PayPal payment notifications against the site's configured merchant account. This flaw allows unauthenticated users to activate or extend memberships by exploiting payments made to any PayPal account they control. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized membership activations.
Original NVD Description
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control.