CVE-2026-88791: Unknown Safe Redirect Manager
Low severity, CVSS 3.4. EPSS: 0.2% chance of exploitation in the next 30 days.
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.
Affected products
- Unknown Safe Redirect Manager: before 2.3.0 (fixed in 2.3.0)
Published 2026-09-30. Last modified 2026-09-30.