Record summary

CVE-2025-14844 has a selected CVSS score of 8.2 (high).

Description

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does not check a user-controlled key, which makes it possible for unauthenticated attackers to leak Stripe SetupIntent client_secret values for any membership.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Membership Plugin – Restrict Content

Browse stellarwp / Membership Plugin – Restrict Content

Default status: unaffected

CVE ListThrough 3.2.16affected

References

6