📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 2h Global supply_chain Software Development and Technology HIGH 7h Global apt Government/Critical Infrastructure CRITICAL 8h Global vulnerability Enterprise Software / Data Analytics CRITICAL 9h Global vulnerability Artificial Intelligence and Technology HIGH 12h Global general Technology and Artificial Intelligence MEDIUM 16h Global general Technology and Artificial Intelligence HIGH 17h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 2h Global supply_chain Software Development and Technology HIGH 7h Global apt Government/Critical Infrastructure CRITICAL 8h Global vulnerability Enterprise Software / Data Analytics CRITICAL 9h Global vulnerability Artificial Intelligence and Technology HIGH 12h Global general Technology and Artificial Intelligence MEDIUM 16h Global general Technology and Artificial Intelligence HIGH 17h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 2h Global supply_chain Software Development and Technology HIGH 7h Global apt Government/Critical Infrastructure CRITICAL 8h Global vulnerability Enterprise Software / Data Analytics CRITICAL 9h Global vulnerability Artificial Intelligence and Technology HIGH 12h Global general Technology and Artificial Intelligence MEDIUM 16h Global general Technology and Artificial Intelligence HIGH 17h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2025-14844

High
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_car
CWE-639 — Weakness Type
Published: Jan 16, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
8.2
🔗 NVD Official
📄 Description (English)

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does not check a user-controlled key, which makes it possible for unauthenticated attackers to leak Stripe SetupIntent client_secret values for any membership.

🤖 AI Executive Summary

The Membership Plugin – Restrict Content for WordPress (versions up to 3.2.16) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to leak Stripe SetupIntent client_secret values. This vulnerability enables unauthorized access to sensitive payment processing information without proper capability checks. The lack of authentication controls combined with missing validation of user-controlled keys creates a direct pathway for attackers to compromise payment data and membership systems.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 25, 2026 20:19
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi organizations utilizing WordPress-based membership and subscription platforms, particularly in banking and fintech sectors relying on Stripe integration. Financial institutions, healthcare providers offering membership services, e-commerce platforms, and educational institutions managing paid content are at high risk. The exposure of Stripe SetupIntent secrets could lead to unauthorized payment processing, fraudulent transactions, and compromise of customer financial data—directly impacting SAMA-regulated entities and organizations subject to NCA cybersecurity requirements. Saudi government agencies and enterprises using this plugin for restricted content delivery face potential data breach and compliance violations.
🏢 Affected Saudi Sectors
Banking and Financial Services E-commerce and Retail Healthcare and Medical Services Education and Online Learning Government and Public Sector Telecommunications Media and Publishing SaaS and Cloud Services
⚖️ Saudi Risk Score (AI)
8.7
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all WordPress installations using Membership Plugin – Restrict Content plugin
2. Disable the plugin immediately if version 3.2.16 or earlier is detected
3. Review Stripe account activity logs for suspicious SetupIntent creation or access patterns
4. Notify affected users of potential exposure to Stripe payment secrets

PATCHING:
1. Update plugin to version 3.2.17 or later immediately
2. Verify patch application by checking plugin version in WordPress admin dashboard
3. Test Stripe integration functionality post-update

COMPENSATING CONTROLS (if immediate patching not possible):
1. Implement Web Application Firewall (WAF) rules to block requests to 'rcp_stripe_create_setup_intent_for_saved_card' function
2. Restrict access to WordPress admin and plugin directories via IP whitelisting
3. Implement rate limiting on Stripe API endpoints
4. Monitor and log all Stripe API calls for anomalies

DETECTION:
1. Monitor WordPress logs for POST requests to wp-admin/admin-ajax.php with action=rcp_stripe_create_setup_intent_for_saved_card
2. Alert on any SetupIntent creation from unauthenticated sessions
3. Review Stripe webhook logs for unexpected SetupIntent events
4. Implement IDS/IPS signatures for CVE-2025-14844 exploitation attempts
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع تثبيتات WordPress التي تستخدم مكون Membership Plugin – Restrict Content
2. تعطيل المكون فوراً إذا تم اكتشاف الإصدار 3.2.16 أو الإصدارات الأقدم
3. مراجعة سجلات نشاط حساب Stripe للبحث عن أنماط إنشاء أو وصول SetupIntent المريبة
4. إخطار المستخدمين المتأثرين بالتعرض المحتمل لأسرار الدفع في Stripe

التصحيح:
1. تحديث المكون إلى الإصدار 3.2.17 أو أحدث فوراً
2. التحقق من تطبيق التصحيح بفحص إصدار المكون في لوحة تحكم WordPress
3. اختبار وظيفة تكامل Stripe بعد التحديث

عناصر التحكم البديلة (إذا لم يكن التصحيح الفوري ممكناً):
1. تنفيذ قواعد جدار حماية تطبيقات الويب (WAF) لحجب الطلبات إلى دالة 'rcp_stripe_create_setup_intent_for_saved_card'
2. تقييد الوصول إلى مجلدات WordPress admin والمكونات الإضافية عبر القائمة البيضاء للعناوين
3. تنفيذ تحديد معدل على نقاط نهاية Stripe API
4. مراقبة وتسجيل جميع استدعاءات Stripe API للكشف عن الشذوذ

الكشف:
1. مراقبة سجلات WordPress للطلبات POST إلى wp-admin/admin-ajax.php مع action=rcp_stripe_create_setup_intent_for_saved_card
2. التنبيه على أي إنشاء SetupIntent من جلسات غير مصرح بها
3. مراجعة سجلات Stripe webhook للأحداث SetupIntent غير المتوقعة
4. تنفيذ توقيعات IDS/IPS لمحاولات استغلال CVE-2025-14844
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1 - Access Control and Authentication 5.2 - User Access Management 6.1 - Cryptography and Data Protection 7.1 - Security Event Logging and Monitoring
🔵 SAMA CSF
ID.AM-1 - Asset Management PR.AC-1 - Access Control PR.AC-2 - Physical and Logical Access Control DE.CM-1 - Detection and Analysis
🟡 ISO 27001:2022
A.5.1.1 - Policies for information security A.6.1.1 - Information security roles and responsibilities A.8.1.1 - User endpoint devices A.9.2.1 - User registration and de-registration A.9.4.3 - Password management A.12.4.1 - Event logging
🟣 PCI DSS v4.0.1
Requirement 1 - Install and maintain a firewall configuration Requirement 2 - Do not use vendor-supplied defaults Requirement 6 - Develop and maintain secure systems and applications Requirement 8 - Identify and authenticate access to system components
📦 Affected Products / CPE 1 entries
liquidweb:restrict_content
📊 CVSS Score
8.2
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityL — Low / Local
AvailabilityN — None / Network
📋 Quick Facts
Severity High
CVSS Score8.2
CWECWE-639
EPSS0.10%
Exploit No
Patch ✓ Yes
Published 2026-01-16
Source Feed nvd
Views 6
🇸🇦 Saudi Risk Score
8.7
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
patch-available CWE-639
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.