CyberRota Analysis
AI-GeneratedThe Simple Membership WordPress plugin prior to version 4.7.8 is vulnerable to account takeover due to improper verification of user creation during registration, allowing unauthenticated attackers to overwrite the primary administrator's account data. This critical vulnerability could lead to unauthorized access and control over the affected WordPress site. WordPress administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.