CVE-2026-4136 | stellarwp Membership Plugin up to 3.2.24 on WordPress rcp_redirect password recovery
A vulnerability described as critical has been identified in stellarwp Membership Plugin up to 3.2.24 on WordPress. This affects an unknown part. The manipulation of the argument rcp_redirect results in weak password recovery.
This vulnerability is cataloged as CVE-2026-4136. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.