CVE-2026-88791 UNKNOWN

CVE-2026-88791

Published: 2026-09-30

Description

The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…