VYPR

Restrict Content

by WordPress

Source repositories

CVEs (9)

  • CVE-2026-9273CriAug 5, 2026
    risk 0.60cvss 9.3epss 0.00

    The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all versions up to, and including, 4.0.0. This is due to the legacy lost-password handler…

  • CVE-2026-32546HigMar 25, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in StellarWP Restrict Content restrict-content allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Content: from n/a through <= 3.2.22.

  • CVE-2025-14844HigJan 16, 2026
    risk 0.46cvss 8.2epss 0.00

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does…

  • CVE-2025-14000MedDec 23, 2025
    risk 0.35cvss 6.4epss 0.00

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user…

  • CVE-2023-47668MedNov 23, 2023
    risk 0.35cvss 5.3epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StellarWP Membership Plugin – Restrict Content plugin <= 3.2.7 versions.

  • CVE-2024-31432MedApr 15, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in StellarWP Restrict Content.This issue affects Restrict Content: from n/a through 3.2.8.

  • CVE-2026-1304MedFeb 18, 2026
    risk 0.29cvss 4.4epss 0.00

    The Membership Plugin – Restrict Content for WordPress is vulnerable to Stored Cross-Site Scripting via multiple invoice settings fields in all versions up to, and including, 3.2.18 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-11351MedDec 11, 2024
    risk 0.27cvss 5.3epss 0.00

    The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8 via the WordPress core search feature. This makes it possible for…

  • CVE-2026-4136MedMar 20, 2026
    risk 0.21cvss 4.3epss 0.00

    The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for…