S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 17, 2026

CVE-2026-1277 Scanner

CVE-2026-1277 Scanner - Open Redirect vulnerability in URL Shortify (WordPress Plugin)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-1277
4.7
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via a crafted link.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
URL Shortify – Simple and Easy URL Shortenerby kaizencoders
0
Updated Aug 22, 2026View on NVD →
Detail

URL Shortify is a WordPress plugin used to shorten URLs on websites. It is widely used by website administrators and digital marketers for managing and tracking the performance of shortened links. This plugin facilitates easier link management and branding for URLs. With its features, users can create custom branded short links that are trackable and manageable. URL Shortify is typically used on WordPress sites to improve link display and user engagement. Its popularity in WordPress community comes from its integration with various marketing tools.

The vulnerability detected in URL Shortify is an Open Redirect. It arises due to insufficient validation on the 'redirect_to' parameter within the promotional dismissal handler. This type of vulnerability allows attackers to redirect users to potentially malicious sites. Open Redirects can facilitate phishing attacks or the distribution of malware. The exploit does not require authentication, making it easier for attackers to target users. This vulnerability underscores the importance of proper validation for redirect functionalities in web applications.

The Open Redirect vulnerability in URL Shortify is specifically related to the 'redirect_to' parameter. Attackers can craft a link that uses this parameter to direct users to a malicious site. The endpoints involved in the exploit include specific promotional and welcome offer handlers in the admin-ajax.php file. The vulnerability affects all versions up to and including 1.12.1. The improper validation allows for manipulation of redirect destinations, posing significant risks if exploited. Correcting this flaw requires updating the plugin to a secure version.

Exploiting this vulnerability can have several serious effects. Users may unintentionally visit malicious sites, leading to potential exposure to phishing attacks or malware infections. This can compromise user data and trust if attackers impersonate legitimate sites. Redirect vulnerabilities undermine the reliability of the URL shortening service, possibly impacting campaigns involving shortened URLs. The vulnerability might also be used in broader attacks against the WordPress infrastructure. For administrators, this could lead to increased support requests or reputational damage to their sites.

REFERENCES

Solution Advice
  • Upgrade the URL Shortify plugin to a version beyond 1.12.1.
  • Implement strict validation checks on URL parameters to prevent Open Redirects.
  • Educate users about the risks of phishing and how to identify malicious links.
  • Consider using security plugins that monitor for and prevent suspicious redirects.
  • Regularly review plugins for security vulnerabilities and apply updates promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.