/Vulnerability Library

URL Shortify <= 1.12.1 - Open Redirect

CVE-2026-1277
Verified

Description

The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via a crafted link.

Severity

Medium

CVSS Score

4.7

Exploit Probability

1%

Published Date

March 16, 2026

Template Author

shivam kamboj

CVE-2026-1277.yaml
4.7Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
CVE ID:
cve-2026-1277
CWE ID:
cwe-601

References

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/url-shortify/url-shortify-1121-unauthenticated-open-redirect-via-redirect-to-parameterhttps://nvd.nist.gov/vuln/detail/CVE-2026-1277

Remediation Steps

Update to the latest version beyond 1.12.1.