{"id":"CVE-2026-80072","title":"The User Registration & Membership  WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which …","summary":"The User Registration & Membership  WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which …","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","cwe":["CWE-601"],"product":"User Registration & Membership","affected":["user_registration_membership < 5.2.8"],"published":"2026-09-13","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:10:17.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80072","references":[{"url":"https://wpscan.com/vulnerability/0af2c06d-87a0-4be7-a409-ffb7ad958aad/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-13T10:42:56.087675Z"},"ingestedAt":"2026-09-14T15:23:07.471Z","epss":0.00171,"epssPercentile":0.06826,"slug":"CVE-2026-80072","body":"## Overview\n\nThe User Registration & Membership  WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}