Executive brief
ARMember Premium is a WordPress plugin used to manage memberships and user access. A security flaw in the plugin's password reset system allows sensitive reset keys to be stored in an insecure format. If an attacker can obtain these keys—for example, by using other existing vulnerabilities—they can reset the password of any user, including site administrators, leading to a full takeover of the website.
Technical details
The ARMember Premium plugin for WordPress (up to version 7.3.1) suffers from an insecure password reset mechanism. While WordPress core securely hashes reset keys, this plugin stores a redundant plaintext copy in the 'arm_reset_password_key' user meta field. An attacker who can read the database (e.g., via a separate SQL injection vulnerability like CVE-2026-5073) can retrieve this plaintext key. This key can then be used with the plugin's custom 'armrp' reset action to bypass standard authentication and set a new password for any user account, including administrators.
Affected products
- ARMember ARMember Premium up to, and including, 7.3.1
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory