{"id":"CVE-2026-88791","title":"The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arb…","summary":"The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arb…","severity":"none","cwe":["CWE-601"],"product":"Safe Redirect Manager","affected":["safe_redirect_manager < 2.3.0"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T06:17:07.690","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88791","references":[{"url":"https://wpscan.com/vulnerability/a8aa5685-e36e-4e1f-a259-fab3910ee550/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T06:58:55.554Z","slug":"CVE-2026-88791","body":"## Overview\n\nThe Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}