CVE-2026-9273 (matched: wordpress)

  • Wednesday, 5th August, 2026
  • 10:05am

A security vulnerability has been found in the Kadence Memberships (previously called Restrict Content) plugin for WordPress, which affects all versions up to 4.0.0. This plugin is used to manage access to members-only content and features on WordPress websites.

The flaw lets unauthenticated bad actors manipulate the plugin's password reset feature to send reset links to a website the attacker controls, instead of to the legitimate account owner. The plugin's public login form exposes the information needed to trigger this attack, so no special access to your site is required to attempt the exploit.

If a legitimate user with an account on your site (including site administrators) clicks the fake reset link, their unique password reset code is sent to the attacker. The attacker can then use that stolen code to take full control of the affected account on your actual website.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-9273

« Back