CVE-2026-88791
EUVD-2026-8961330.09.2026, 06:17
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration