Junglewise Threat Intelligence

CVE-2026-66712: Simple Membership broken access control in page access

CVE-2026-66712 · Severity: high · CVSS 7.5 · Published 2026-08-06

Executive brief

Simple Membership is a WordPress plugin that manages user registration and content access control for membership sites. An unauthenticated attacker can bypass access restrictions and view or interact with protected pages and functionality they should not be permitted to access, potentially exposing private member data or allowing unauthorized actions.

Technical details

Simple Membership plugin versions 4.7.8 and earlier contain a broken access control vulnerability that allows unauthenticated users to bypass authorization checks on protected pages. The vulnerability is reachable over the network without authentication or user interaction required. An attacker can exploit this to access restricted content, view other members' data, or perform actions intended only for authenticated users with proper permissions. The vulnerability was patched in version 4.7.9, and administrators should update immediately.

Affected products

  • Simple Membership Simple Membership <=4.7.8

Timeline

  • 2026-08-05: disclosed: Vulnerability reported and disclosed
  • 2026-08-05: patched: Fixed in version 4.7.9

References