Sceawere
Vulnerability Detail
CVE-2026-103427UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Simple Membership Stored XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- wpinsider-1
- Product
- Simple Membership
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'country' parameter in all versions up to, and including, 4.8.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauthenticated attackers may also exploit this vulnerability when the plugin's Enable Free Membership feature is turned on, as it permits anonymous front-end registration and profile submission.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-10T07:16:40.120Z",
"pubdate": "2026-10-10T07:16:40.120Z",
"executiveSummary": "The Simple Membership plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability impacting versions 4.8.4 and earlier.\nThe vulnerability arises from improper handling of user-supplied input within the 'country' parameter, which fails to undergo adequate sanitization or output encoding.\nThis flaw allows malicious actors to inject arbitrary JavaScript payloads into the application, which are subsequently stored and executed in the browsers of users viewing the affected pages.\nThe attack surface includes authenticated users with subscriber-level privileges or higher. Furthermore, if the 'Enable Free Membership' feature is active, unauthenticated remote attackers can exploit the flaw via anonymous front-end registration and profile submission forms.\nSuccessful exploitation permits unauthorized script execution within the context of the victim's session, potentially leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The security implications are critical for site integrity and user data confidentiality, as the injected scripts execute in the browser environment of any user accessing the compromised profile or membership page.",
"technicalDetails": "The vulnerability resides within the user profile management functionality of the Simple Membership plugin. Specifically, the 'country' input field fails to implement server-side input sanitization or proper context-aware output escaping when rendering stored data back to the browser.\nThe attack vector involves a malicious actor submitting a crafted payload—typically containing script tags or event handlers (e.g., <script>alert(1)</script> or onmouseover events)—through the 'country' field in a membership profile update or registration form. Because the plugin does not validate this input, the malicious string is persisted directly into the WordPress database.\nWhen an administrative user or another legitimate site member navigates to a page where this profile information is rendered, the application echoes the stored, unescaped payload directly into the HTML Document Object Model (DOM).\nThe browser interprets the injected data as legitimate executable code rather than plain text. This allows for the execution of arbitrary JavaScript within the security context of the victim's session. The scope of the attack is amplified by the plugin's 'Enable Free Membership' feature, which bypasses traditional authentication requirements by allowing anonymous front-end registration, effectively lowering the barrier for exploitation to any remote, unauthenticated attacker.\nThe exploit flow follows a standard Stored XSS lifecycle: first, the attacker identifies the vulnerable 'country' parameter endpoint; second, the attacker submits a malicious script as the parameter value; third, the server saves the payload without sanitization; fourth, a target user accesses the stored content; finally, the victim's browser executes the script automatically.\nThe post-exploitation impact includes the potential for document object manipulation, unauthorized API requests using the victim's authentication cookies, redirection to malicious domains, and the exfiltration of sensitive session tokens or PII (Personally Identifiable Information). Since the injected payload is stored, the attack remains persistent until the malicious entry is manually purged from the database or the underlying code is corrected to implement strict input validation and output encoding."
}