PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9273 stellarwp CVE debrief

The Membership Plugin – Kadence Memberships plugin for WordPress, formerly Restrict Content, is vulnerable to password reset link poisoning leading to account takeover. This critical vulnerability exists in all versions up to, and including, 4.0.0 due to the legacy lost-password handler rc_process_lost_password_form() consuming the attacker-controlled rc_redirect POST parameter into two unvalidated sinks. The nonce required to reach the handler is broadcast by the public [login_form] shortcode to any anonymous visitor, allowing unauthenticated attackers to issue a password-reset request for any account, including administrators. When the victim clicks the link, the reset key leaks to the attacker, who can replay it against the legitimate site to complete account takeover. Affected deployments should review official advisories and upgrade to patched versions. Additional security measures, such as restricting access to login and password reset functionality, monitoring for suspicious requests, and implementing IP blocking and rate limiting, are recommended.

Vendor
stellarwp
Product
Membership Plugin – Kadence Memberships
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-08-05
Advisory published
2026-08-05
Advisory updated
2026-08-05

Who should care

Administrators and users of the Membership Plugin – Kadence Memberships plugin for WordPress should be aware of this critical vulnerability and take immediate action to assess and mitigate the risk. This vulnerability can lead to account takeover, potentially allowing attackers to gain unauthorized access to sensitive information and perform malicious actions.

Technical summary

The Membership Plugin – Kadence Memberships plugin for WordPress is vulnerable to password reset link poisoning, potentially leading to account takeover. The issue exists in the legacy lost-password handler rc_process_lost_password_form(), which consumes the attacker-controlled rc_redirect POST parameter into two unvalidated sinks. A nonce required to reach the handler is broadcast by the public [login_form] shortcode to any anonymous visitor, allowing unauthenticated attackers to issue a password-reset request for any account.

Defensive priority

CVE-2026-9273 is a critical vulnerability in the Membership Plugin – Kadence Memberships plugin for WordPress, allowing for password reset link poisoning and potential account takeover. Immediate attention is required to assess and mitigate this vulnerability.

Recommended defensive actions

  • Review and update the Membership Plugin – Kadence Memberships to the latest version
  • Restrict access to the login and password reset functionality
  • Monitor for suspicious password reset requests and account activities
  • Implement additional security measures, such as IP blocking and rate limiting
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The vulnerability exists in the Membership Plugin – Kadence Memberships plugin for WordPress, specifically in the legacy lost-password handler rc_process_lost_password_form(). The plugin is vulnerable to password reset link poisoning, potentially leading to account takeover. The issue arises from the consumption of the attacker-controlled rc_redirect POST parameter into two unvalidated sinks. A nonce required to reach the handler is broadcast by the public [login_form] shortcode to any anonymous visitor, allowing unauthenticated attackers to issue a password-reset request for any account. The CVE record and NVD entry provide details on the vulnerability, but further information about affected versions and patched releases is needed.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9273 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9273

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9273 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9273

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.