---
id: CVE-2026-97318
title: >-
  The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27
  does not properly validate a giveaway's parent page URL before saving it and
  later redirecting visitors to it, allowing unauthenticated attackers to make
  the site…
summary: >-
  The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27
  does not properly validate a giveaway's parent page URL before saving it and
  later redirecting visitors to it, allowing unauthenticated attackers to make
  the site…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-601
product: Giveaways and Contests by RafflePress
affected:
  - giveaways_and_contests_by_rafflepress < 1.12.27
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:00:34.733'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97318'
references:
  - url: 'https://wpscan.com/vulnerability/a171b0f1-b2d2-4482-b44f-bd4a1f3b223b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00136
epssPercentile: 0.02561
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-02T10:44:58.194558Z'
ingestedAt: '2026-10-02T06:11:20.479Z'
---

## Overview

The Giveaways and Contests by RafflePress  WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
