Description
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does not check a user-controlled key, which makes it possible for unauthenticated attackers to leak Stripe SetupIntent client_secret values for any membership.
References (6)
Core 6
Core References
Technical Description
https://cwe.mitre.org/data/definitions/639.html
Scores
CVSS v3
8.2
EPSS
0.0010
EPSS Percentile
28.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (2)
liquidweb/restrict_content
< 3.2.17
stellarwp/Membership Plugin – Restrict Content
< 3.2.16
Published
Jan 16, 2026
Tracked Since
Feb 18, 2026