GHSA-xxpw-g4gr-qqvvLowCVSS 3.4
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect...
🔗 CVE IDs covered (1)
📋 Description
The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path.