Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-5076 — ARMember Premium <= 7.3.1 Full Admin Account Takeover | Kitploit
Tools/GitHubGitHub/shootcannon/cve-2026-5076
Password AttacksVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubshootcannon/cve-2026-5076

CVE-2026-5076

ARMember Premium <= 7.3.1 Full Admin Account Takeover

View Repository
2 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-5076 - ARMember Password Reset Vulnerability

telegram-cloud-photo-size-5-6129916611100610908-y

Vulnerability Information

ItemDetail
CVE IDCVE-2026-5076
PluginARMember – Membership Plugin & Content Restriction
Affected VersionPremium <= 7.3.1
Patched Version7.3.2
CVSS Score9.8 (Critical)
CWECWE-640: Weak Password Recovery
TypeInsecure Password Reset Mechanism → Plaintext Key Storage
Attack VectorNetwork / Remote / Unauthenticated (via SQLi chain)
Active Installations30,000+ (Premium)
Discovered ByWordfence Threat Intelligence
Publication DateJune 3, 2026

Related CVEs

CVETypeSeverity
CVE-2026-5076Insecure Password Reset — Plaintext Key Storage9.8 Critical
CVE-2026-5073Unauthenticated SQL Injection (ORDER BY)9.8 Critical
CVE-2026-5074Unauthenticated SQL Injection (WHERE)

Description

ARMember Premium versions 7.3.1 and below are affected by a critical vulnerability involving insecure password reset handling. The plugin stores password reset keys in plaintext, allowing attackers to leverage additional vulnerabilities such as SQL Injection to obtain valid reset tokens and potentially compromise user accounts.

Impact

  • Account takeover
  • Unauthorized password reset
  • Privilege escalation
  • Administrative account compromise

Remediation

  • Upgrade to ARMember Premium 7.3.2 or later.
  • Rotate credentials for affected accounts.
  • Review logs for suspicious password reset activity.
  • Apply all security updates related to CVE-2026-5073 and CVE-2026-5074.

Severity

MetricValue
CVSS v3.19.8
SeverityCritical
Authentication RequiredNo
User InteractionNone
Download Tool
9.8 Critical
Attack Complexity
Low