{"id":"CVE-2026-88791","published":"2026-09-30T06:17:07.690","lastModified":"2026-09-30T06:17:07.690","description":"The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/a8aa5685-e36e-4e1f-a259-fab3910ee550/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}