Membership Plugin – Restrict Content <= 3.2.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Invoice Settings
Membership Plugin – Kadence Memberships
Minimum safe version
3.2.25
Update to 3.2.25 or later to address 16 fixable vulnerabilities
Membership Plugin – Restrict Content <= 3.2.20 - Unauthenticated Privilege Escalation via 'rcp_level'
Membership Plugin – Restrict Content <= 3.2.24 - Unvalidated Redirect in Password Reset Flow via rcp_redirect
CVE-2026-32546
CVE-2025-14844
CVE-2025-14000
WordPress Restrict Content Plugin <= 3.2.13 is vulnerable to Sensitive Data Exposure
CVE-2024-31432
CVE-2023-47668
Restrict Content <= 3.2.7 - Information Exposure via legacy log file
WordPress Restrict Content Plugin <= 3.2.4 is vulnerable to Cross Site Scripting (XSS)
Restrict Content <= 3.2.2 - Missing Authorization to Notice Dismissal
CVE-2023-3182
WordPress Restrict Content Plugin < 3.2.3 is vulnerable to Broken Access Control
WordPress Restrict Content Plugin < 3.2.3 is vulnerable to Cross Site Scripting (XSS)
Restrict Content <= 3.2.2 - Reflected Cross-Site Scripting