{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-9273/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-9273"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Membership Plugin - Kadence Memberships (\u003c= 4.0.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","account-takeover","wordpress","cve-2026-9273"],"_cs_type":"advisory","_cs_vendors":["Kadence"],"content_html":"\u003cp\u003eThe Membership Plugin - Kadence Memberships plugin for WordPress (all versions up to and including 4.0.0) contains a critical vulnerability related to improper input validation in its legacy lost-password handler. The handler, \u003ccode\u003erc_process_lost_password_form()\u003c/code\u003e, improperly trusts the user-supplied \u003ccode\u003erc_redirect\u003c/code\u003e POST parameter. Attackers can leverage this to inject arbitrary URLs into the password reset process. Because the necessary nonce for the reset request is available to any anonymous visitor via the \u003ccode\u003e[login_form]\u003c/code\u003e shortcode, unauthenticated attackers can craft requests that direct victims to an external, attacker-controlled domain. When a victim clicks the malicious link, the sensitive reset token is leaked to the attacker's server. The attacker can then use this token on the legitimate WordPress site to reset the password and achieve account takeover, including for administrative accounts. This issue presents a high risk due to the ease of exploitation and the potential for full site compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker visits a public page on the target WordPress site to obtain a valid nonce from the rendered \u003ccode\u003e[login_form]\u003c/code\u003e shortcode.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the target user account, such as an administrator, to initiate a password reset.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request to the legacy lost-password handler endpoint.\u003c/li\u003e\n\u003cli\u003eThe request includes the harvested nonce and a malicious \u003ccode\u003erc_redirect\u003c/code\u003e parameter pointing to an attacker-controlled host.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the request and generates a password reset email containing a link that redirects the victim to the attacker's server.\u003c/li\u003e\n\u003cli\u003eThe victim receives and clicks the password reset link, inadvertently sending the reset key and login information to the attacker's controlled host.\u003c/li\u003e\n\u003cli\u003eAttacker captures the reset key from their server logs.\u003c/li\u003e\n\u003cli\u003eAttacker uses the leaked key to complete the password reset flow on the legitimate site, gaining control over the victim's account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform unauthorized account takeovers. This impact is significant as it includes administrative accounts, potentially leading to full site compromise, sensitive data exfiltration, and the execution of arbitrary code via administrative plugin or theme installation capabilities within WordPress.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Kadence Memberships plugin to a version addressing CVE-2026-9273 immediately.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests targeting legacy password reset endpoints or those containing unexpected \u003ccode\u003erc_redirect\u003c/code\u003e parameters pointing to external domains.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to validate or block the \u003ccode\u003erc_redirect\u003c/code\u003e parameter if it contains non-local or non-whitelisted domain components.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T08:05:58Z","date_published":"2026-08-05T08:05:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-kadence-memberships-poisoning/","summary":"The Kadence Memberships plugin for WordPress is vulnerable to password reset link poisoning, allowing unauthenticated attackers to hijack accounts by redirecting users to malicious hosts to harvest reset tokens.","title":"CVE-2026-9273 Password Reset Poisoning in Kadence Memberships","url":"https://feed.craftedsignal.io/briefs/2026-08-kadence-memberships-poisoning/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-9273","version":"https://jsonfeed.org/version/1.1"}