The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Sep 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path. | |
| Title | Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-30T06:00:22.862Z
Reserved: 2026-09-10T08:03:03.141Z
Link: CVE-2026-88791
No data.
Status : Received
Published: 2026-09-30T06:17:07.690
Modified: 2026-09-30T06:17:07.690
Link: CVE-2026-88791
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.