


Perceptive Security
SOC/SIEM Consultancy

The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account t…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 07:01:24
Source:
nvd.nist.gov
Web Technologies, Identity & Access
The Kadence Memberships plugin for WordPress (formerly Restrict Content) contains a password reset link poisoning vulnerability affecting all versions up to and including 4.0.0. The legacy lost-password handler rc_process_lost_password_form() accepts an attacker-controlled rc_redirect POST parameter without validation, redirecting password reset emails to attacker-controlled hosts. The nonce required to trigger this handler is publicly exposed via the [login_form] shortcode, making it accessible to unauthenticated attackers. An attacker can issue a password reset for any account, including administrators, causing the reset key to be sent to an attacker-controlled URL. When the victim clicks the poisoned link, the reset key is leaked to the attacker, who can replay it against the legitimate site to complete a full account takeover. The vulnerability stems from two unvalidated sinks in legacy/includes/forms.php at lines 243 and 306. A patch was released in version 4.0.1.
Technical details
Mitigation steps:
Affected products:
Kadence Memberships WordPress Plugin
Restrict Content WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-9273
https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L207
https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L243
https://plugins.trac.wordpress.org/browser/restrict-content/tags/4.0.0/legacy/includes/forms.php#L306
https://plugins.trac.wordpress.org/browser/restrict-content/trunk/legacy/includes/forms.php#L243
https://plugins.trac.wordpress.org/browser/restrict-content/trunk/legacy/includes/forms.php#L306
https://plugins.trac.wordpress.org/changeset?new=3549742%40restrict-content%2Ftags%2F4.0.1&old=3529319%40restrict-content%2Ftags%2F4.0.0
https://www.wordfence.com/threat-intel/vulnerabilities/id/ca38c423-2df8-4f20-bd95-2ecd84167a7f?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
