CVE-2026-97337 WordPress Simple Membership 未授权数据修改与信息泄露漏洞
影响未授权攻击者可劫持激活邮件并激活任意会员账户,获取明文密码
WordPress 的 Simple Membership 插件在 4.8.3 及之前版本中,resend-activation 和 email-activation 端点存在未授权访问问题。这些端点由 SwpmInitTimeTasks::check_and_do_email_activation() 在前端 init 时调用,缺少认证、nonce、权限和归属校验。攻击者可控制 $_POST['email'] 参数,将任意待激活会员的激活邮件及包含用户名和明文密码的注册完成邮件重定向到攻击者指定地址,并激活该会员账户。
影响范围
Simple Membership 插件 4.8.3 及之前版本(WordPress 环境)。
漏洞详情
漏洞类型为未授权数据修改与敏感信息泄露。成因是前端初始化时调用的邮件激活处理逻辑未做任何身份与权限校验,且收件地址直接取自攻击者可控的 POST 参数,覆盖了会员注册邮箱。攻击者无需登录即可触发重发激活邮件,将邮件劫持到自己的邮箱,从而获得会员用户名和明文密码,并完成账户激活。
利用条件与风险
利用无需认证,攻击者只需知道或枚举待激活会员信息即可发起。实战中可批量劫持新注册会员账户,导致账户接管和敏感信息泄露,风险较高。
修复建议
建议升级到官方修复版本(暂无公开信息)。临时缓解措施包括禁用或限制相关激活端点访问、对前端邮件激活请求增加 nonce 与权限校验,或暂时停用该插件。
The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via the resend-activation and email-activation endpoints. The endpoints are dispatched from SwpmInitTimeTasks::check_and_do_email_activation() on frontend init with no authentication, nonce, capability, or ownership check, and the recipient address used by SwpmRegistration::send_reg_email() is taken from an attacker-controlled $_POST[’email’] parameter (overriding the member’s registered address). This makes it possible for unauthenticated attackers to redirect an arbitrary pending member’s activation email — and the follow-up ‘registration complete’ email containing the member’s username and plaintext password — to an attacker-chosen address, and to then activate that member’s account without their consent.