Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/zycoder0day/cve-2026-5076
Password AttacksVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAuthentication
GitHubzycoder0day/cve-2026-5076

CVE-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext password reset key storage.

View Repository
433 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

☠️ CVE-2026-5076

ARMember Premium <= 7.3.1

Insecure Password Reset Mechanism → Full Admin Account Takeover

Plaintext Password Reset Keys Stored in Database + SQL Injection = Complete Admin Takeover


📋 Vulnerability Information

ItemDetail
CVE IDCVE-2026-5076
PluginARMember – Membership Plugin & Content Restriction
Affected VersionPremium <= 7.3.1
Patched Version7.3.2
CVSS Score9.8 Critical
CWECWE-640: Weak Password Recovery
TypeInsecure Password Reset Mechanism → Plaintext Key Storage
Attack VectorNetwork / Remote / Unauthenticated (via SQLi chain)
Active Installations30,000+ (Premium)
DiscovererWordfence Threat Intelligence
Publication DateJune 3, 2026

Related CVEs (Same Advisory)

CVETypeSeverity
CVE-2026-5076Insecure Password Reset — Plaintext Key Storage9.8 Critical
CVE-2026-5073Unauthenticated SQL Injection (ORDER BY)9.8 Critical
CVE-2026-5074Unauthenticated SQL Injection (WHERE)9.8 Critical

🎯 Summary

Three critical vulnerabilities in the WordPress plugin ARMember Premium <= 7.3.1 that, when chained together, allow full administrator account takeover without authentication:

  1. CVE-2026-5076 — Password reset key stored in plaintext in wp_usermeta (arm_reset_password_key), not hashed as per WordPress standard
  2. CVE-2026-5073 — SQL Injection in the order parameter of the AJAX handler arm_directory_paging_action()
  3. CVE-2026-5074 — SQL Injection in the filter parameter of the AJAX handler arm_directory_paging_action()

Direct consequence of CVE-2026-5076: Anyone with read access to the database (via SQLi, backup exposure, etc.) can read the password reset key in plaintext and immediately use it to reset any account's password — without needing to crack it.


🔬 Technical Analysis

Root Cause #1: Plaintext Key Storage (CVE-2026-5076)

Standard WordPress stores the password reset key in the user_activation_key column in hashed form using wp_hash(). ARMember stores a copy of the same key in wp_usermeta with meta_key arm_reset_password_key — but in PLAINTEXT:```php // FILE: armember-membership/core/class.arm_member_forms.php // Fungsi: arm_lost_password_action()

// WordPress menyimpan HASHED key (aman) $key = wp_generate_password(20, false); $wp_key = $wpdb->get_var( $wpdb->prepare("SELECT user_activation_key FROM $wpdb->users WHERE user_login=%s", $user_login) );

// ARMember menyimpan PLAINTEXT key (VULNERABLE!) update_user_meta($user_id, 'arm_reset_password_key', $wp_key); // ^^^^^^ // Ini adalah key ASLI yang bisa langsung dipakai

**Critical Issue**: `$wp_key` here is the key generated by `wp_generate_password(20, false)` — 20 alphanumeric characters. WordPress hashes this key before storing it in `user_activation_key`, but ARMember stores it **before hashing** or stores a separate **unhashed** copy.

### Root Cause #2: Key Persistence Bug

When `get_password_reset_key()` is called (WordPress core), a new key is generated and hashed. However, this function **does NOT update** `arm_reset_password_key`:```php
// WordPress core: get_password_reset_key($user)
// - Generate key baru
// - Hash key → simpan di user_activation_key
// - Return key plaintext
// - TAPI: arm_reset_password_key TIDAK diupdate!

As a result, the old plaintext key remains stored permanently in arm_reset_password_key even after the user performs a password reset. This key can be used repeatedly until the meta key is explicitly deleted.

Root Cause #3: SQL Injection (CVE-2026-5073/5074)

AJAX handler arm_directory_paging_action() has a nonce check via arm_check_user_cap(), but the order and filter parameters go directly into the SQL query without sanitization:```php // FILE: armember-membership/core/class.arm_member_forms.php // Fungsi: arm_directory_paging_action()

// Nonce check (dibutuhkan nonce valid) $nonce_check = $this->arm_check_user_cap();

// ORDER BY injection — langsung ke SQL tanpa sanitasi! $orderby = "u.{$arm_member} {$order_dir}"; // $order_dir dari $_POST['order'] → LANGSUNG ke ORDER BY

// WHERE injection via filter if (!empty($filter)) { $where .= " AND " . $filter; // ← LANGSUNG concatenation! }

**ORDER BY Exploitation**: The `order` parameter is inserted into the SQL `ORDER BY` clause. Because there is no sanitization, an attacker can inject a subquery:```sql
-- Payload SQLi via parameter order
ORDER BY u.ID ASC, IF(COND, 1, EXP(710))

-- COND = TRUE  → IF returns 1 → ORDER BY 1 → response normal (besar)
-- COND = FALSE → IF returns EXP(710) → MySQL overflow ERROR → response 90B

This Oracle is immune to network latency because it distinguishes TRUE/FALSE based on error vs success, not response time.


⛓️ Attack Chain Roadmap```

╔══════════════════════════════════════════════════════════════════════════════════╗ ║ CVE-2026-5076 FULL CHAIN ATTACK ROADMAP ║ ║ ARMember Premium <= 7.3.1 → Unauthenticated Admin Takeover ║ ╚══════════════════════════════════════════════════════════════════════════════════╝

Download Tool