Home

Description

The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET parameter is passed directly to WordPress's `wp_redirect()` function instead of the domain-restricted `wp_safe_redirect()`. While `esc_url_raw()` is applied to sanitize malformed URLs, it does not restrict the redirect destination to the local domain, allowing an attacker to craft a specially formed link that redirects users to potentially malicious external URLs after logout, which could be used to facilitate phishing attacks.

PUBLISHED Reserved 2026-04-13 | Published 2026-04-13 | Updated 2026-04-24 | Assigner Wordfence




MEDIUM: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

Product status

Default status
unaffected

Any version
affected

Timeline

2026-04-13:Vendor Notified
2026-04-13:Disclosed

Credits

Louis Deschanel finder

Pascal SUN finder

Anthony Cihan finder

References

www.wordfence.com/...-9544-49b7-941d-3b7f509fdfdf?source=cve

plugins.trac.wordpress.org/...udes/functions-ur-template.php

plugins.trac.wordpress.org/...udes/functions-ur-template.php

cve.org (CVE-2026-6203)

nvd.nist.gov (CVE-2026-6203)

Download JSON