CVE-2026-39600: WordPress Aculect AI Companion plugin <= 0.8.1 - Unvalidated Redirects and Forwards vulnerability
Published Oct 2, 2026
·Updated
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.1.
Affected Software
1 affected component
Mehul Gohil Aculect AI Companion<=0.8.1
Event History
Oct 2, 2026
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are within the affected version range?
Aculect AI Companion versions through 0.8.1 are affected. The available data does not identify a fixed release.
2
What does an attacker need to exploit this issue?
The CVSS vector indicates network access is sufficient and no attacker privileges are required. Exploitation requires user interaction, consistent with phishing through a redirect to an untrusted site.