Junglewise Threat Intelligence

CVE-2026-12093: Simple Membership WordPress plugin authorization bypass in Stripe webhooks

CVE-2026-12093 · Severity: medium · CVSS 5.3 · Published 2026-06-18

Technologies: Wpinsider-1 Simple Membership.

Executive brief

The Simple Membership plugin for WordPress, which manages user subscriptions and access, contains a flaw that allows unauthorized individuals to deactivate member accounts. By sending a fake payment refund notification, an attacker can trick the system into marking a legitimate user's account as inactive. This can lead to service disruptions for customers and automated cancellation emails being sent without cause.

Technical details

The Simple Membership plugin for WordPress suffers from a missing authorization check (CWE-862) in its Stripe webhook handling logic. Unauthenticated attackers can forge a 'charge.refunded' webhook event containing a target's subscription ID. If the 'stripe-webhook-signing-secret' is not configured (the default state), the plugin fails to verify the authenticity of the request via HMAC, subsequently setting the member's 'account_state' to 'inactive'. This triggers cancellation hooks and modifies transaction records. The vulnerability is mitigated if a webhook signing secret is properly configured.

Affected products

  • wpinsider-1 Simple Membership up to, and including, 4.7.5

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory

References