PT-2026-103034 · Undefined · Undefined

·

CVE-2026-88791

·

Publicado

2026-09-30

·

Atualizado

2026-09-30

CVSS v3.1

3.4

Baixa

VetorAV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-88791

Produtos afetados

Undefined