ARMember
cpe:2.3:a:armemberplugin:armember:*:*:*:*:wordpress:*:*
- <= 7.3.1
A vulnerability exists in the ARMember Premium plugin for WordPress, in all versions through 7.3.1, due to an insecure password reset mechanism. When a user requests a password reset, the plugin saves a plaintext copy of the reset key in the 'arm_reset_password_key' user meta field, alongside the hashed key that WordPress core securely stores. This plaintext key can be used with the plugin's custom 'armrp' reset action to change the password for any user. This vulnerability allows unauthenticated attackers to extract the plaintext reset key and take over any user account, including those of administrators, especially when combined with other vulnerabilities like SQL Injection.
Exploitation of this vulnerability could lead to unauthorized password resets and account takeovers, including administrative accounts.
Users are advised to update to version 7.3.2 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.