Sceawere

Vulnerability Detail

CVE-2026-88785UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Simple Membership Password Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
8h ago
Vendor
Unknown
Product
Simple Membership
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The Simple Membership WordPress plugin before 4.8.3 does not avoid transmitting a newly registered member's plaintext password in a URL query string when an optional auto-login-after-registration feature is enabled, exposing the credential in browser history and in web server, proxy, and CDN access logs to anyone able to read them.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-10-11T07:17:27.030Z",
  "pubdate": "2026-10-11T07:17:27.030Z",
  "executiveSummary": "The Simple Membership WordPress plugin contains a sensitive information disclosure vulnerability occurring when the optional auto-login-after-registration feature is enabled.\nThe root cause of this vulnerability is the transmission of a user's plaintext password within the HTTP GET request query string during the automatic authentication process.\nThis design flaw results in the exposure of credentials in plaintext across various logs, including browser history, web server access logs, reverse proxy logs, and CDN logs.\nThe vulnerability affects all versions of the Simple Membership plugin prior to 4.8.3.\nThe risk implication is significant, as any actor with authorized or unauthorized access to the underlying infrastructure, log aggregation systems, or user browser history can intercept these plaintext passwords.\nExploitation does not require active interception of network traffic, as the sensitive data is persisted in log files, providing a substantial window of opportunity for credential harvesting.\nAdministrators are urged to upgrade to version 4.8.3 or later to remediate this security deficiency.",
  "technicalDetails": "The vulnerability resides in the authentication workflow triggered after a new user completes the registration process when the 'auto-login-after-registration' feature is active.\nUnder normal secure design patterns, authentication credentials should be transmitted via the HTTP POST method within the request body to prevent logging of sensitive parameters.\nIn this specific implementation, the plugin improperly constructs an HTTP GET request that appends the newly created user's plaintext password directly to the URL query string.\nThe attack flow proceeds as follows: 1) A user registers for an account; 2) The Simple Membership plugin automatically initiates an authentication request for the user; 3) The authentication request is generated using a GET method containing a parameter representing the password; 4) The web server processes this request and records the full URL, including the password, in its standard access logs.\nBecause the credential is part of the URL, it is subsequently stored in plaintext within browser history, web server access logs, and potentially intermediate network devices such as load balancers, reverse proxies, and Content Delivery Networks (CDNs).\nAny entity or automated process with read access to these log files—including system administrators, security information and event management (SIEM) systems, or malicious actors who have gained local or network file system access—can retrieve the plaintext credentials.\nFurthermore, if the application is accessed over unencrypted HTTP, or if the traffic is terminated at a proxy that logs the full URI, the sensitive information is exposed during transit and at rest.\nThe vulnerability is inherent to the plugin's authentication logic and does not require complex exploitation techniques; it is a passive information exposure resulting from improper handling of sensitive data.\nPost-exploitation, an attacker who obtains these logs can gain unauthorized access to newly registered user accounts, potentially leading to privilege escalation if the accounts are assigned elevated roles upon registration, or facilitating cross-service credential stuffing attacks."
}
CVE-2026-88785: Simple Membership Password Information Disclosure (MEDIUM Severity, CVSS: 4.7) | Sceawere