VYPR

Membership Plugin – Restrict Content

by WordPress

Source repositories

CVEs (5)

  • CVE-2026-1321HigMar 5, 2026
    risk 0.46cvss 8.1epss 0.00

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter…

  • CVE-2025-14844HigJan 16, 2026
    risk 0.46cvss 8.2epss 0.00

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does…

  • CVE-2025-14000MedDec 23, 2025
    risk 0.35cvss 6.4epss 0.00

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user…

  • CVE-2024-11090MedJan 26, 2025
    risk 0.27cvss 5.3epss 0.00

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from…

  • CVE-2026-4136MedMar 20, 2026
    risk 0.21cvss 4.3epss 0.00

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for…