Impact
The Membership Plugin – Kadence Memberships for WordPress, in all versions up to and including 4.0.0, has a critical flaw that allows an attacker to poison password‑reset links. By sending a user a reset email that contains a crafted redirect URL controlled by the attacker, the victim’s reset key is exposed when they click the link. The attacker can then replay the leaked key on the legitimate site to reset the account and take control. This vulnerability is a classic example of exploiting user‑supplied input that bypasses validation and is catalogued under CWE‑640.
Affected Systems
The affected product is the StellarWP Membership Plugin – Kadence Memberships, a WordPress plugin. The vulnerability exists in every released version through 4.0.0; any WordPress site running that legacy version is susceptible.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity flaw that allows account takeover. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog; however, the attack vector is inferred to be unauthenticated and remote, as the attacker only needs to send a reset email and provide a malicious link to a victim. Once the victim follows the link, the reset key is leaked, allowing immediate account takeover without further interaction.
OpenCVE Enrichment