CVE-2026-80072 - User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect Parameters
CVE ID :CVE-2026-80072
Published : Sept. 13, 2026, 6:16 a.m. | 50 minutes ago
Description :The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 13, 2026, 6:16 a.m. | 50 minutes ago
Description :The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...