CVE-2026-9273: Critical Password Reset Link Poisoning Vulnerability in Kadence Memberships Plugin
A critical vulnerability (CVE-2026-9273, CVSS 9.3) exists in the Kadence Memberships plugin for WordPress, allowing unauthenticated attackers to poison password reset links, leading to account takeovers. The vulnerability affects all versions up to and including 4.0.0. Immediate patching is recommended to prevent potential account takeovers, especially for administrator accounts.