SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15930

CRITICAL · CVSS 9.4 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Simple Membership WordPress plugin prior to version 4.7.8 is vulnerable to account takeover due to improper verification of user creation during registration, allowing unauthenticated attackers to overwrite the primary administrator's account data. This critical vulnerability could lead to unauthorized access and control over the affected WordPress site. WordPress administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-15930
Severity
CRITICAL
CVSS
9.4
EPSS
0.25%
WordPress

Original NVD Description

The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.