CVE Vulnerabilities

CVE-2026-14936

Insufficient Verification of Data Authenticity

Published: Aug 06, 2026 | Modified: Aug 07, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the sites own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to an arbitrary PayPal account they control.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

References