CVE-2026-5076 - ARMember Password Reset Vulnerability
| Item | Detail |
|---|
| CVE ID | CVE-2026-5076 |
| Plugin | ARMember – Membership Plugin & Content Restriction |
| Affected Version | Premium <= 7.3.1 |
| Patched Version | 7.3.2 |
| CVSS Score | 9.8 (Critical) |
| CWE | CWE-640: Weak Password Recovery |
| Type | Insecure Password Reset Mechanism → Plaintext Key Storage |
| Attack Vector | Network / Remote / Unauthenticated (via SQLi chain) |
| Active Installations | 30,000+ (Premium) |
| Discovered By | Wordfence Threat Intelligence |
| Publication Date | June 3, 2026 |
| CVE | Type | Severity |
|---|
| CVE-2026-5076 | Insecure Password Reset — Plaintext Key Storage | 9.8 Critical |
| CVE-2026-5073 | Unauthenticated SQL Injection (ORDER BY) | 9.8 Critical |
| CVE-2026-5074 | Unauthenticated SQL Injection (WHERE) |
Description
ARMember Premium versions 7.3.1 and below are affected by a critical vulnerability involving insecure password reset handling. The plugin stores password reset keys in plaintext, allowing attackers to leverage additional vulnerabilities such as SQL Injection to obtain valid reset tokens and potentially compromise user accounts.
Impact
- Account takeover
- Unauthorized password reset
- Privilege escalation
- Administrative account compromise
- Upgrade to ARMember Premium 7.3.2 or later.
- Rotate credentials for affected accounts.
- Review logs for suspicious password reset activity.
- Apply all security updates related to CVE-2026-5073 and CVE-2026-5074.
Severity
| Metric | Value |
|---|
| CVSS v3.1 | 9.8 |
| Severity | Critical |
| Authentication Required | No |
| User Interaction | None |
|