CVE-2026-104401
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects Memberful - Membership Plugin: from n/a through 1.81.2.
- Published Oct 5, 2026
- CVSS 4.3 medium
- 0.2% chance of exploitation in the next 30 days (EPSS)