CVE-2026-97318: Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
Installations using the Giveaways and Contests by RafflePress WordPress plugin with a version earlier than 1.12.27 are affected.
What does an attacker need to exploit this issue?
An attacker does not need to authenticate. They need to supply an arbitrary external URL through the giveaway parent_url parameter so it is saved and later used by giveaway confirmation or referral links.
Which links can be abused for redirects?
The site’s giveaway confirmation links and referral links can be made to redirect visitors to an attacker-chosen external site after the malicious parent page URL has been saved.