Description
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthenticated Open Redirect
Action: Patch Immediately
AI Analysis

Impact

The plugin fails to validate a parent page URL before storing it, and later uses that stored URL to redirect visitors automatically. An unauthenticated attacker can supply an arbitrary external address, causing visitors to be redirected to a site of the attacker's choosing. This redirect can be used for phishing, malware delivery, and other social engineering attacks. The vulnerability itself does not expose code execution or data exfiltration directly but can compromise user trust or lead to indirect compromise through the redirected site.

Affected Systems

WordPress sites using the Giveaways and Contests by RafflePress plugin version 1.12.26 or earlier are affected. No other specific sub‑versions or vendors are listed.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not present in the CISA KEV catalog, indicating no known exploitation reports at the time of analysis. Nonetheless, an attacker can invoke the flaw simply by crafting a URL containing the compromised parent_url value, requiring no authentication. Because the flaw relies on a stored open redirect, it is relatively easy to exploit and could be employed in mass phishing campaigns. The lack of an existing exploit does not lessen the potential for future abuse.

Generated by OpenCVE AI on October 2, 2026 at 07:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the RafflePress plugin to version 1.12.27 or later, which removes the validation flaw.
  • If a patch is unavailable, uninstall the plugin or disable the feature that stores and uses the parent_url parameter to prevent redirects.
  • Implement Web Application Firewall rules that block or sanitize redirect URLs supplied by the plugin, such as checking for valid domain or no redirects to external sites.

Generated by OpenCVE AI on October 2, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601

Fri, 02 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
Title Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via 'parent_url' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T06:00:27.170Z

Reserved: 2026-09-24T11:27:52.068Z

Link: CVE-2026-97318

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T06:16:43.803

Modified: 2026-10-02T06:16:43.803

Link: CVE-2026-97318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T07:30:07Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')