CVE-2026-88791: Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Safe Redirect Managerto a version that resolves this vulnerability.Fixed in 2.3.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
WordPress sites using Safe Redirect Manager versions before 2.3.0 are exposed if they have a wildcard redirect rule configured with an absolute URL destination.
What does an attacker need to exploit it?
An attacker does not need to authenticate. They need to send a request using a crafted path that triggers the affected wildcard redirect rule.
Are default plugin configurations affected?
The issue requires a wildcard redirect rule pointing to an absolute URL. The provided information does not establish that such a rule is present by default.
What should be checked if an immediate update is not possible?
Review configured redirect rules and identify wildcard rules whose destinations are absolute URLs. Removing or disabling those rules prevents the described vulnerable condition.