Impact
The Membership Plugin – Restrict Content contains a stored cross‑site scripting flaw in several invoice settings fields. Administrators or higher privileged users can insert arbitrary web script code, which is subsequently rendered in the invoice template and executed when a visitor views the page. The vulnerability is classified as CWE‑79 and allows injected code to run in the context of the web page.
Affected Systems
The affected product is StellarWP Membership Plugin – Restrict Content for WordPress. All released versions up to and including 3.2.18 can be impacted; later releases are not listed as affected.
Risk and Exploitability
The impact score is CVSS 4.4, indicating moderate severity. EPSS is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, implying a low current exploitation likelihood. Exploitation requires authenticated access at the Administrator level or higher; the injected script is stored and executed when any user accesses a page that renders the invoice template. The attack vector is therefore authenticated stored XSS.
OpenCVE Enrichment