What is CVE-2026-9273?
CVE-2026-9273 is a vulnerability in the Kadence Memberships (formerly Restrict Content) WordPress plugin up to version 4.0.0, allowing password reset link poisoning and account takeover. The issue stems from the legacy lost-password handler. Users should update the plugin immediately.
Azərbaycanca: CVE-2026-9273 zəifliyi Kadence Memberships (əvvəllər Restrict Content) WordPress plugin-inin 4.0.0 və aşağı versiyalarında aşkarlanıb. Bu, "lost-password" funksiyasında "password reset link poisoning" vasitəsilə hesabın ələ keçirilməsinə imkan verir. Plugin-i son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which WordPress plugin is affected by CVE-2026-9273?
CVE-2026-9273 affects the Kadence Memberships (formerly known as Restrict Content) WordPress plugin.
How does this vulnerability allow account takeover?
The vulnerability allows account takeover through password reset link poisoning in the "lost-password" function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.