← back
CVE-2026-1277mediumobserved exploitationCWE-601

URL Shortify <= 1.12.1 - Unauthenticated Open Redirect via 'redirect_to' Parameter

50Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 4.7epss 0.6%
from disclosure to weapon
Published on NVDFeb 18
VulnCheck+43d
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
yesVulnCheck
The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via a crafted link.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N