top of page
perceptive_background_267k.jpg

The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account t…

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 07:01:24

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The Kadence Memberships plugin for WordPress (formerly Restrict Content) contains a password reset link poisoning vulnerability affecting all versions up to and including 4.0.0. The legacy lost-password handler rc_process_lost_password_form() accepts an attacker-controlled rc_redirect POST parameter without validation, redirecting password reset emails to attacker-controlled hosts. The nonce required to trigger this handler is publicly exposed via the [login_form] shortcode, making it accessible to unauthenticated attackers. An attacker can issue a password reset for any account, including administrators, causing the reset key to be sent to an attacker-controlled URL. When the victim clicks the poisoned link, the reset key is leaked to the attacker, who can replay it against the legitimate site to complete a full account takeover. The vulnerability stems from two unvalidated sinks in legacy/includes/forms.php at lines 243 and 306. A patch was released in version 4.0.1.

Technical details

Mitigation steps:

Affected products:

Kadence Memberships WordPress Plugin
Restrict Content WordPress Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page