Executive brief
The Simple Membership plugin for WordPress, which manages member subscriptions and payments, contains a security flaw in how it handles payment notifications from Stripe. An attacker can send a fake notification that injects malicious code into the website's management dashboard. If a site administrator views their dashboard, this code could allow the attacker to take control of the website or steal sensitive administrative information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the Simple Membership plugin due to insufficient validation of Stripe webhook requests. When a Stripe signing secret is not configured (the default state), the plugin processes unauthenticated POST requests to the 'swpm_process_stripe_subscription' endpoint. An attacker can provide a malicious payload in the 'api_version' field of the JSON body. If the version string is prefixed with an older date, the plugin stores the value in the 'swpm_stripe_received_api_old_version' option and subsequently renders it unescaped within a WordPress admin notice. This allows for arbitrary JavaScript execution in the context of a logged-in administrator. The issue is fixed in version 4.7.5.
Affected products
- Simple Membership Team Simple Membership < 4.7.5
Timeline
- 2026-06-15: disclosed: Publicly published by WPScan
- 2026-07-06: advisory: NVD publication date
- 2026-07-06: patched: Fixed in version 4.7.5