Security Advisory

CVE-2026-15931

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-03 06:00:13
Last updated 2026-08-03 17:06:38
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when displaying it in the administration dashboard, allowing unauthenticated attackers to store arbitrary JavaScript that executes in an administrator's session.