Membership Plugin – Restrict Content Missing Authentication Vulnerability (CVE-2025-14844) — High Severity

A significant security flaw has been identified in the popular Membership Plugin – Restrict Content for WordPress. This vulnerability, tracked as CVE-2025-14844, could allow unauthorized individuals to access sensitive payment-related information, posing a high risk to websites utilizing the plugin for managing memberships and processing payments via Stripe.

CVE Details

This vulnerability impacts the Membership Plugin – Restrict Content for WordPress. It was publicly disclosed on January 16, 2026, and has a High severity rating, with a CVSS score of 8.2. The status of this vulnerability is currently ‘Analyzed’.

Affected Products

The security flaw affects all versions of the Membership Plugin – Restrict Content for WordPress up to, and including, version 3.2.16. If you are running any version within this range, your website is potentially vulnerable.

Current Status

The vulnerability has been thoroughly analyzed. The core issue stems from a missing authentication check within the rcp_stripe_create_setup_intent_for_saved_card function. Additionally, the plugin fails to properly validate a user-controlled key. Together, these weaknesses allow unauthenticated attackers—meaning anyone, without needing to log in or have any special permissions—to obtain Stripe SetupIntent client_secret values. These values are crucial for setting up future payments and could be misused if exposed.

Severity Level

This vulnerability is rated as HIGH severity. A CVSS score of 8.2 indicates a significant risk. The ease of exploitation by unauthenticated attackers, combined with the potential to leak sensitive payment setup information (Stripe SetupIntent client_secret values), makes this a critical issue. Such a leak could lead to unauthorized access to payment processes or further malicious activities involving your members’ payment data.

Possible Solutions

To secure your WordPress website and protect your members’ payment information, it is crucial to update the Membership Plugin – Restrict Content immediately. Developers have addressed this vulnerability in version 3.2.17. Users are strongly advised to update to version 3.2.17 or a newer patched version as soon as possible. Regular updates are a cornerstone of website security, ensuring you benefit from the latest fixes and protections against emerging threats.

References

https://cwe.mitre.org/data/definitions/639.html

https://docs.stripe.com/api/setup_intents/object

https://plugins.trac.wordpress.org/browser/restrict-content/tags/3.2.16/core/includes/gateways/stripe/functions.php#L848

https://plugins.trac.wordpress.org/browser/restrict-content/tags/3.2.16/core/includes/gateways/stripe/functions.php#L987

https://plugins.trac.wordpress.org/changeset/3438168/restrict-content/tags/3.2.17/core/includes/gateways/stripe/functions.php

https://www.wordfence.com/threat-intel/vulnerabilities/id/0c28545d-c7cd-469f-bccf-90e8b52fd4e7?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.