The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.
CVE-2026-88764
NONE
Updated Sep 13, 2026
WordPress
CVE Details
CVE ID
CVE-2026-88764
Published Date
Sep 13, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory