Executive brief
Simple Membership is a WordPress plugin that manages user memberships and access control on WordPress sites. A broken access control vulnerability in version 4.8.2 and earlier allows users with the Contributor role to access pages or perform actions they shouldn't be permitted to, such as viewing other users' data or performing administrative functions.
Technical details
A broken access control vulnerability exists in Simple Membership versions 4.8.2 and earlier due to insufficient authorization checks. An attacker with a Contributor role (low privilege WordPress account) can bypass access restrictions to view and potentially modify restricted pages and data that should only be accessible to higher-privilege users. The vulnerability requires authentication (a valid Contributor account) to exploit. A patch is available in version 4.8.3 and later.
Affected products
- WordPress Simple Membership 4.8.2 and earlier
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in version 4.8.3
- 2026-09-17: advisory