CVE-2026-88791
— UNSCOREDPublished 2026-09-30 · Updated 2026-09-30
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.