Unrated severityNVD Advisory· Published Jul 6, 2026· Updated Jul 6, 2026
Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version
CVE-2026-11855
Description
The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in the context of a logged-in administrator.
Affected products
1- Range: <4.7.5
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/217cb606-a0f2-4427-9262-cfe1cc90474e/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.