LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-4136

Published
CVSS4.3
Severitymedium
WeaknessCWE-640
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.2.24. This is due to insufficient validation on the redirect url supplied via the 'rcp_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the password reset email to potentially malicious sites if they can successfully trick them into performing an action.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-4136

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-4136.