Sceawere
Vulnerability Detail
CVE-2026-104401UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Memberful Plugin Sensitive Data Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 10h ago
- Vendor
- Memberful
- Product
- Memberful - Membership Plugin
- Attack Type
- Exposure of Sensitive System Information to an Unauthorized Control Sphere
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-05T09:17:08.200Z",
"pubdate": "2026-10-05T09:17:08.200Z",
"executiveSummary": "The Memberful - Membership Plugin for WordPress is affected by an Exposure of Sensitive System Information vulnerability, categorized under the unauthorized control sphere weakness.\nThis vulnerability allows an attacker to retrieve embedded sensitive data that should remain restricted from public or unauthorized access.\nThe issue affects Memberful - Membership Plugin versions from n/a through 1.81.2.\nThe risk implication is high, as the exposure of sensitive configuration or system data can lead to further exploitation, unauthorized access to membership management, or the compromise of user-related data.\nAn attacker can exploit this vulnerability without sophisticated prerequisites, potentially leveraging automated requests to extract information directly from the affected WordPress installation.\nThe vulnerability highlights a failure in the plugin's access control mechanisms or improper handling of data serialization within its internal API endpoints or front-end components.",
"technicalDetails": "The vulnerability identified in Memberful - Membership Plugin (n/a through 1.81.2) constitutes an Information Disclosure flaw where sensitive system information is exposed to an unauthorized control sphere.\nRoot Cause: The plugin incorrectly handles the retrieval and exposure of internal data structures, likely due to improper input validation or insufficient authorization checks on specific endpoints or functions designed to surface plugin state information.\nAttack Flow: An attacker interacts with the WordPress REST API or other registered plugin hooks that process and return system-level data. By sending crafted HTTP requests, the attacker can force the plugin to output sensitive configuration parameters, internal API keys, or embedded metadata that are inadvertently serialized and transmitted in the response body.\nVulnerable Component: The issue resides in the plugin's data processing logic, specifically where membership-related configurations are rendered or retrieved for front-end integration. Because these endpoints fail to verify the requestor's authorization level, sensitive internal system data is rendered accessible to any unauthenticated or low-privileged user capable of triggering these endpoints.\nExploitation Method: Exploitation typically involves identifying the specific endpoint responsible for plugin data retrieval and performing an unauthorized GET request. If the endpoint does not perform proper nonce validation or user role verification (e.g., checking for 'manage_options' capabilities), the plugin returns the sensitive system information in JSON format. This payload often contains data that can be used to facilitate deeper infiltration of the WordPress instance or associated Memberful services.\nImpact: Post-exploitation impact includes, but is not limited to, the exposure of plugin environment variables, service credentials, or member database identifiers. This information significantly reduces the attacker's burden to conduct more advanced attacks, such as lateral movement within the WordPress environment or unauthorized manipulation of member subscriptions.\nNetwork Exposure: The vulnerability is exploitable over the network, assuming the attacker has HTTP/HTTPS access to the target WordPress instance. No advanced knowledge of the server architecture is required, making this an accessible target for automated vulnerability scanning tools."
}