nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-1304 CVE-2026-1304
MEDIUM
Membership Plugin – Restrict Content <= 3.2.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Invoice Settings
Record summary
CVE-2026-1304 has a selected CVSS score of 4.4 (medium).
Description
The Membership Plugin – Restrict Content for WordPress is vulnerable to Stored Cross-Site Scripting via multiple invoice settings fields in all versions up to, and including, 3.2.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Membership Plugin – Restrict ContentBrowse stellarwp / Membership Plugin – Restrict ContentDefault status: unaffected | CVE List | Through 3.2.18 | affected |
References
5plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/restrict-content/tags/3.2.16/core/includes/admin/settings/settings.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/restrict-content/tags/3.2.16/core/templates/invoice.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3448964%40restrict-content&new=3448964%40restrict-content&sfp_email=&sfph_mail= wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/cdd563b7-a1b9-4d99-9a6e-c8acf9dda619?source=cve