Membership Plugin – Restrict Content
Membership Plugin – Restrict Content restricts WordPress content by membership level and manages access permissions for registered users.
Membership Plugin – Restrict Content (restrict-content) is a WordPress plugin with 11 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 9.3.
restrict-contentCVE-2026-9273: Kadence Memberships reset redirect can leak administrator reset keys
Membership Plugin – Kadence Memberships through 4.0.0 lets an unauthenticated visitor obtain the nonce exposed by the public [login_form] shortcode and submit an attacker-controlled rc_redirect value to rc_process_lost_password_form(). The legacy handler carries that value into wp_redirect() and into add_query_arg() in rc_send_password_reset_email(), causing the target user's legitimate reset email to point at an attacker-controlled host. If the victim follows that link, the valid reset key and login leak to the attacker, who can replay them against the real site and take over the account, including an administrator account.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-9273
Kadence Memberships reset redirect can leak administrator reset keys
Membership Plugin – Kadence Memberships through 4.0.0 lets an unauthenticated visitor obtain the nonce exposed by the public [login_form] shortcode and submit an attacker-controlled rc_redirect value to rc_process_lost_password_form(). The legacy handler carries that value into wp_redirect() and into add_query_arg() in rc_send_password_reset_email(), causing the target user's legitimate reset email to point at an attacker-controlled host. If the victim follows that link, the valid reset key and login leak to the attacker, who can replay them against the real site and take over the account, including an administrator account.
|
4.0.1 |
CVE9.3
NVDPending
|
| Mar 25, 2026 |
CVE-2026-32546
Restrict Content: A security weakness
Restrict Content is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 3.2.22. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
3.2.23 |
CVE7.5
NVDPending
|
| Mar 20, 2026 |
CVE-2026-4136
Membership Plugin – Restrict Content: A security weakness
Membership Plugin – Restrict Content is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 05, 2026 |
CVE-2026-1321
Membership Plugin – Restrict Content: Privilege escalation or authentication bypass
Membership Plugin – Restrict Content is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Feb 18, 2026 |
CVE-2026-1304
Restrict Content: Cross-site scripting
Restrict Content is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.4
NVDPending
|
| Jan 16, 2026 |
CVE-2025-14844
Membership Plugin – Restrict Content: A security weakness
Membership Plugin – Restrict Content is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.2
NVD7.5
|
| Dec 23, 2025 |
CVE-2025-14000
Membership Plugin – Restrict Content: Cross-site scripting
Membership Plugin – Restrict Content is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jan 26, 2025 |
CVE-2024-11090
Membership Plugin – Restrict Content: Sensitive information exposure
Membership Plugin – Restrict Content is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Apr 15, 2024 |
CVE-2024-31432
Restrict Content: A security weakness
Restrict Content is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Nov 23, 2023 |
CVE-2023-47668
Restrict Content: A security weakness
Restrict Content is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Jul 17, 2023 |
CVE-2023-3182
Membership: Cross-site scripting
Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD6.1
|