🔐 CVE Alert

CVE-2026-5076

CRITICAL 9.8

ARMember Premium <= 7.3.1 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the hashed key that WordPress core stores securely in `wp_users.user_activation_key`. The plaintext key stored in `wp_usermeta` can be used with the plugin's custom `armrp` reset action to set a new password for any user. Combined with another vulnerability such as SQL Injection (CVE-2026-5073, CVE-2026-5074), this makes it possible for unauthenticated attackers to extract the plaintext reset key and take over any user account, including administrators.

CWE CWE-287
Vendor armember
Product armember premium – membership plugin, content restriction, member levels, user profile & user signup
Published Jun 2, 2026
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for armember armember premium – membership plugin, content restriction, member levels, user profile & user signup

Be the first to know when new critical vulnerabilities affecting armember armember premium – membership plugin, content restriction, member levels, user profile & user signup are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

armember / ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup
0 ≤ 7.3.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/6b15eca5-fd47-4f8f-8ade-3a90e0bfc110?source=cve codecanyon.net: https://codecanyon.net/item/armember-complete-wordpress-membership-system/17785056

Credits

Phú