CVE detail
CVE-2026-12093
The Simple Membership plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.7.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to deactivate arbitrary member accounts by forging a charge.refunded webhook event containing a victim's subscription ID, setting the target member's account_state to 'inactive' and triggering cancellation hooks, transaction-record status changes, and cancellation notification emails. This vulnerability is exploitable only on installations where no Stripe webhook signing secret has been configured, which is the default out-of-the-box state; sites that have configured the stripe-webhook-signing-secret option are routed to the properly verified HMAC path and are not affected.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 15, 2026 to June 21, 2026)Wordfence
henticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source 6.5 CVSS Rating 6.5 (Medium) CVE-ID CVE-2026-8118 Patch Status Patched Published Jun 18, 2026 Affected Software Royal Addons for Elementor – Addons and Templates Kit for Elementor [royal-elementor-addons] Researcher Jack Taylor More Details > RTMKit SALESmanago & Leado
vendorwww.wordfence.comJun 25, 2026, 7:02 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/2f91a7c3-ee0e-48e9-aa5f-dfc1160bbc09?source=cvewww.wordfence.com
No excerpt available.
Third Party Advisorywww.wordfence.comJun 18, 2026, 6:16 AM - https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3573852%40simple-membership&new=3573852%40simple-membership&sfp_email=&sfph_mail=plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 18, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.7.4/ipn/swpm_handle_subsc_ipn.php#L381plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 18, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.7.4/ipn/swpm-stripe-webhook-handler.php#L71plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 18, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.7.4/ipn/swpm-stripe-webhook-handler.php#L297plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 18, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.7.4/classes/class.swpm-wp-loaded-tasks.php#L96plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 18, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.7.3/ipn/swpm_handle_subsc_ipn.php#L381plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 18, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.7.3/ipn/swpm-stripe-webhook-handler.php#L71plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 18, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.7.3/ipn/swpm-stripe-webhook-handler.php#L297plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 18, 2026, 6:16 AM - https://plugins.trac.wordpress.org/browser/simple-membership/tags/4.7.3/classes/class.swpm-wp-loaded-tasks.php#L96plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 18, 2026, 6:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-47755CVSS 6.5 · Medium
ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve p…
- CVE-2026-65916CVSS 7.2 · High
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, dele…
- CVE-2026-65895CVSS 8.2 · High
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege…
- CVE-2026-65537CVSS 4.3 · Medium
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
- CVE-2026-65531CVSS 4.8 · Medium
Unauthenticated Broken Access Control in Qubely <= 1.8.14 versions.
- CVE-2026-65530CVSS 4.3 · Medium
Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.