Description
The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via a crafted link.
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
* (semver)
Timeline
| 2026-01-21: | Vendor Notified |
| 2026-02-17: | Disclosed |
Credits
Tarcísio Luchesi De Almeida Silva
References
www.wordfence.com/...-47ca-4b2f-9ff9-275bd8b1c106?source=cve
plugins.trac.wordpress.org/...1.11.4/lite/includes/Promo.php
plugins.trac.wordpress.org/...shortify&sfp_email=&sfph_mail=