What is CVE-2026-15931?
The Simple Membership WordPress plugin (<4.7.8) fails to sanitise a subscriber name from an unauthenticated payment approval request and does not escape it in the admin dashboard. This allows unauthenticated attackers to inject arbitrary JavaScript, leading to a Stored XSS attack. Updating to the latest plugin version is strongly recommended.
Azərbaycanca: Simple Membership WordPress plaginində (4.7.8-dən əvvəlki versiyalarda) autentifikasiya olunmamış ödəniş sorğusundan alınan abunəçi adı sanitizasiya edilmir və admin panelində ekranlaşdırılmır. Bu, autentifikasiya olunmamış hücumçulara admin panelində icra olunan Stored XSS hücumu təşkil etməyə imkan verir. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Simple Membership WordPress plugin are affected by CVE-2026-15931?
Versions prior to 4.7.8 are affected.
How to mitigate the Stored XSS attack in CVE-2026-15931?
Updating to the latest plugin version is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.