MEDIUM
CVE-2026-88764
CVSS
5.4
Description
The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.
Weakness (CWE)
CWE-269
Improper Privilege Management
EPSS Score
0.14%
Probability of exploitation in next 30 days
3.5th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.