Impact
The plugin fails to validate a parent page URL before storing it, and later uses that stored URL to redirect visitors automatically. An unauthenticated attacker can supply an arbitrary external address, causing visitors to be redirected to a site of the attacker's choosing. This redirect can be used for phishing, malware delivery, and other social engineering attacks. The vulnerability itself does not expose code execution or data exfiltration directly but can compromise user trust or lead to indirect compromise through the redirected site.
Affected Systems
WordPress sites using the Giveaways and Contests by RafflePress plugin version 1.12.26 or earlier are affected. No other specific sub‑versions or vendors are listed.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not present in the CISA KEV catalog, indicating no known exploitation reports at the time of analysis. Nonetheless, an attacker can invoke the flaw simply by crafting a URL containing the compromised parent_url value, requiring no authentication. Because the flaw relies on a stored open redirect, it is relatively easy to exploit and could be employed in mass phishing campaigns. The lack of an existing exploit does not lessen the potential for future abuse.
OpenCVE Enrichment