← WordPress Vulnerabilities
WordPress security by component

Membership Plugin – Restrict Content

Membership Plugin – Restrict Content restricts WordPress content by membership level and manages access permissions for registered users.

Membership Plugin – Restrict Content (restrict-content) is a WordPress plugin with 11 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 9.3.

Plugin slug: restrict-content

CVE-2026-9273: Kadence Memberships reset redirect can leak administrator reset keys

Membership Plugin – Kadence Memberships through 4.0.0 lets an unauthenticated visitor obtain the nonce exposed by the public [login_form] shortcode and submit an attacker-controlled rc_redirect value to rc_process_lost_password_form(). The legacy handler carries that value into wp_redirect() and into add_query_arg() in rc_send_password_reset_email(), causing the target user's legitimate reset email to point at an attacker-controlled host. If the victim follows that link, the valid reset key and login leak to the attacker, who can replay them against the real site and take over the account, including an administrator account.

PublishedAug 05, 2026
Known safe version4.0.1
Published vulnerabilities for restrict-content
Safe version
Aug 05, 2026 CVE-2026-9273
Kadence Memberships reset redirect can leak administrator reset keys
Membership Plugin – Kadence Memberships through 4.0.0 lets an unauthenticated visitor obtain the nonce exposed by the public [login_form] shortcode and submit an attacker-controlled rc_redirect value to rc_process_lost_password_form(). The legacy handler carries that value into wp_redirect() and into add_query_arg() in rc_send_password_reset_email(), causing the target user's legitimate reset email to point at an attacker-controlled host. If the victim follows that link, the valid reset key and login leak to the attacker, who can replay them against the real site and take over the account, including an administrator account.
4.0.1
CVE9.3
NVDPending
Mar 25, 2026 CVE-2026-32546
Restrict Content: A security weakness
Restrict Content is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 3.2.22. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
3.2.23
CVE7.5
NVDPending
Mar 20, 2026 CVE-2026-4136
Membership Plugin – Restrict Content: A security weakness
Membership Plugin – Restrict Content is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Mar 05, 2026 CVE-2026-1321
Membership Plugin – Restrict Content: Privilege escalation or authentication bypass
Membership Plugin – Restrict Content is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.1
NVDPending
Feb 18, 2026 CVE-2026-1304
Restrict Content: Cross-site scripting
Restrict Content is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.4
NVDPending
Jan 16, 2026 CVE-2025-14844
Membership Plugin – Restrict Content: A security weakness
Membership Plugin – Restrict Content is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.2
NVD7.5
Dec 23, 2025 CVE-2025-14000
Membership Plugin – Restrict Content: Cross-site scripting
Membership Plugin – Restrict Content is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.4
NVDPending
Jan 26, 2025 CVE-2024-11090
Membership Plugin – Restrict Content: Sensitive information exposure
Membership Plugin – Restrict Content is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVD7.5
Apr 15, 2024 CVE-2024-31432
Restrict Content: A security weakness
Restrict Content is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVDPending
Nov 23, 2023 CVE-2023-47668
Restrict Content: A security weakness
Restrict Content is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVD7.5
Jul 17, 2023 CVE-2023-3182
Membership: Cross-site scripting
Membership is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVEPending
NVD6.1