---
id: CVE-2026-88791
title: >-
  The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly
  validate the redirect destination when a wildcard redirect rule to an absolute
  URL is configured, allowing unauthenticated attackers to redirect visitors to
  an arb…
summary: >-
  The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly
  validate the redirect destination when a wildcard redirect rule to an absolute
  URL is configured, allowing unauthenticated attackers to redirect visitors to
  an arb…
severity: none
cwe:
  - CWE-601
product: Safe Redirect Manager
affected:
  - safe_redirect_manager < 2.3.0
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:07.690'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88791'
references:
  - url: 'https://wpscan.com/vulnerability/a8aa5685-e36e-4e1f-a259-fab3910ee550/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.554Z'
---

## Overview

The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
