CVE-2026-1277
MEDIUM EXPLOITED NUCLEIWordPress URL Shortify <1.12.1 - Open Redirect
Title source: llmDescription
The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via a crafted link.
Exploits (1)
github
WORKING POC
by Sechunt3r · shellpoc
https://github.com/Sechunt3r/CVE-POCs/tree/main/CVE-2026-1277
Nuclei Templates (1)
URL Shortify <= 1.12.1 - Open Redirect
MEDIUMVERIFIEDby Shivam Kamboj
References (3)
Scores
CVSS v3
4.7
EPSS
0.0029
EPSS Percentile
52.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Details
VulnCheck KEV
2026-04-02
CWE
CWE-601
Status
published
Products (1)
kaizencoders/URL Shortify – Simple and Easy URL Shortener
< 1.12.1
Published
Feb 18, 2026
Tracked Since
Feb 18, 2026