CVE-2026-1277Disclosure

LOWCVSS 4.7 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' parameter in the promotional dismissal handler. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites via a crafted link.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-18); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-18: 2Mentions · 2026-03-17: 1Mentions · 2026-04-06: 1Active Exploitation · 2026-04-06: 1Technical Details · 2026-02-18: 2Technical Details · 2026-03-17: 1Technical Details · 2026-04-06: 102-1803-1704-06
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-182
Disclosure2
2026-03-171
Disclosure1
2026-04-061
Active Exploitation1
Full discourse4 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers are weaponizing open redirects in CVE-2026-1277 and CVE-2026-2153 to bypass email security filters. Phishing campaigns leveraged trusted domains like Google Meet to steal credentials, then moved laterally through cloud environments. Runtime segmentation helps contain post-compromise lateral movement. #Phishing #ZeroTrust :link: Full TRC analysis: https://aviatrix.ai/threat-research-center/phishing-campaigns-exploit-open-redirects-2026

    Post summary

    Attackers are exploiting CVE‑2026‑1277 and CVE‑2026‑2153 open‑redirect vulnerabilities in phishing campaigns to bypass email filters and steal credentials.

    0001060
    1.9K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1277 - medium 🚨 URL Shortify <= 1.12.1 - Open Redirect > The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1277 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2026‑1277, a medium‑severity Open Redirect flaw that affects all versions of the WordPress URL Shortify plugin up to 1.12.1, but it does not provide a PoC, exploit, or remediation guidance.

    00001147
    901 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1277 📊 Severity: 4.7 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1277 #CVE-2026-1277 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/azP7lBd6s9

    Post summary

    The tweet announces the new CVE‑2026‑1277, noting a medium severity of 4.7 and that it affects WordPress, but offers no additional technical, exploit, or patch information.

    0000041
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1277 The URL Shortify plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.12.1 due to insufficient validation on the 'redirect_to' pa… https://www.cve.org/CVERecord?id=CVE-2026-1277

    Post summary

    CVE-2026-1277 is a disclosed Open Redirect vulnerability in the URL Shortify WordPress plugin up to version 1.12.1, caused by insufficient validation of the 'redirect_to' parameter.

    00000136
    56.4K followersView on X

Explore more