CVE-2026-88791: Unknown Safe Redirect Manager

Low severity, CVSS 3.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.

Affected products

  • Unknown Safe Redirect Manager: before 2.3.0 (fixed in 2.3.0)

Published 2026-09-30. Last modified 2026-09-30.