THREAT OPS › Threat News › [NVD] CVE-2026-88764 (MEDIUM 5.4) — The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher,
[NVD] CVE-2026-88764 (MEDIUM 5.4) — The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher,
CVE-2026-88764 CVSS: 5.4 MEDIUM Published: 2026-09-13T06:16:25.350
The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-priced membership while being granted a higher, more privileged membership level.
Indicators of compromise
- CVE-2026-88764cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-88764