CVE-2025-14844

Source
https://cve.org/CVERecord?id=CVE-2025-14844
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14844.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-14844
Published
2026-01-16T10:16:04.330Z
Modified
2026-03-14T08:45:24.740471Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcpstripecreatesetupintentforsavedcard' function due to missing capability check. Additionally, the plugin does not check a user-controlled key, which makes it possible for unauthenticated attackers to leak Stripe SetupIntent clientsecret values for any membership.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14844.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "3.2.17"
            }
        ]
    }
]