6.1
CVE-2026-97318
- EPSS 0.15%
- Veröffentlicht 02.10.2026 06:00:27
- Zuletzt bearbeitet 02.10.2026 18:00:34
- Erkennungen
Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter
Giveaways and Contests by RafflePress <= 1.12.26 - Unauthenticated Open Redirect
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
Mögliche Gegenmaßnahme
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers: Update to version 1.12.27, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerUnknown
≫
Produkt
Giveaways and Contests by RafflePress
Default Statusunaffected
Version
0
Version <
1.12.27
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers
Version
*-1.12.26
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.033 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
https://wpscan.com/vulnerability/a171b0f1-b2d2-4482-b44f-bd4a1f3b223b/
https://www.wordfence.com/threat-intel/vulnerabilities/id/f9fce4d3-77c7-4e80-a3a9-1eff8ff95aa7