What is CVE-2026-15930?
A critical vulnerability in the Simple Membership WordPress plugin before version 4.7.8 allows unauthenticated attackers to overwrite the primary administrator's account data, including the email address, by manipulating the returned user ID during a failed registration. Affected users should immediately update the plugin to the latest version.
Azərbaycanca: Simple Membership WordPress plugin-in 4.7.8-dən əvvəlki versiyalarında autentifikasiya olunmamış hücumçulara qeydiyyat zamanı istifadəçi ID-sini manipulyasiya edərək əsas administrator hesabının məlumatlarını (email daxil olmaqla) üzərinə yazmağa imkan verən kritik boşluqdur. Təsirlənmiş istifadəçilər dərhal plugin-i ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the Simple Membership plugin are affected by the vulnerability?
Versions of the Simple Membership plugin before 4.7.8 are affected by this critical vulnerability.
What can an unauthenticated attacker overwrite on the primary administrator account through this vulnerability?
An unauthenticated attacker can overwrite the primary administrator's account data, including the email address.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.