CVE-2026-1277

MEDIUM EXPLOITED NUCLEI

WordPress URL Shortify <1.12.1 - Open Redirect

Title source: llm

Description

The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via a crafted link.

Exploits (1)

github WORKING POC
by Sechunt3r · shellpoc
https://github.com/Sechunt3r/CVE-POCs/tree/main/CVE-2026-1277

Nuclei Templates (1)

URL Shortify <= 1.12.1 - Open Redirect
MEDIUMVERIFIEDby Shivam Kamboj

Scores

CVSS v3 4.7
EPSS 0.0029
EPSS Percentile 52.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Details

VulnCheck KEV 2026-04-02
CWE
CWE-601
Status published
Products (1)
kaizencoders/URL Shortify – Simple and Easy URL Shortener < 1.12.1
Published Feb 18, 2026
Tracked Since Feb 18, 2026