CVE-2026-11855
Simple Membership
The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in the context of a logged-in administrator.
- CVSS
- 8.8
- EPSS
- 0.28% 19.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.06