Sceawere
Vulnerability Detail
CVE-2026-97318UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Open Redirect in RafflePress Plugin
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 17h ago
- Vendor
- Unknown
- Product
- Giveaways and Contests by RafflePress
- Attack Type
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting visitors to it, allowing unauthenticated attackers to make the site's own giveaway confirmation and referral links redirect visitors to an arbitrary external site.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-02T06:16:43.803Z",
"pubdate": "2026-10-02T06:16:43.803Z",
"executiveSummary": "The Giveaways and Contests by RafflePress WordPress plugin, in versions prior to 1.12.27, contains an Open Redirect vulnerability. This flaw arises from insufficient validation of the 'parent page URL' parameter when configuring giveaway settings.\nThe vulnerability allows an unauthenticated attacker to manipulate redirection logic, enabling the redirection of site visitors to arbitrary, malicious external URLs via legitimate giveaway confirmation and referral links. Because these links appear to originate from the trusted domain, the impact includes high-confidence phishing, credential harvesting, and the bypass of security filters.\nThe risk is categorized as significant due to the ease of exploitation and the ability for attackers to leverage the reputation of the compromised site to conduct social engineering attacks. No authentication is required to trigger this redirection, and the attack surface is exposed to any user interacting with the plugin's giveaway functionality.",
"technicalDetails": "The root cause of this vulnerability is improper input validation within the RafflePress plugin’s configuration logic. Specifically, the plugin permits the submission of an arbitrary URL for the giveaway's parent page without enforcing a whitelist or validation check against the site’s own origin or trusted domains.\nWhen a user or administrator configures a giveaway, the plugin saves the 'parent page URL' provided. This URL is later utilized by the plugin's internal redirection mechanisms during the confirmation process or when a user clicks a referral link. Because the application fails to verify that the target URL is local or explicitly permitted, it blindly processes the provided input.\nThe attack flow proceeds as follows: First, an unauthenticated attacker identifies the vulnerable endpoint responsible for processing giveaway referrals or confirmation redirects. Second, the attacker submits a payload—a malicious external URL—as the 'parent page URL' within the plugin's settings or through a crafted request if the configuration interface is exposed. Once the plugin stores this untrusted data, any visitor who subsequently interacts with the specific giveaway referral or confirmation mechanism is subjected to an HTTP 302 or similar redirect to the attacker-controlled site.\nThis behavior facilitates a classic Open Redirect attack. By weaponizing the trusted domain of the WordPress site, attackers can successfully bypass security measures such as email link reputation filters or user skepticism regarding the destination of a link. The impact of this post-exploitation behavior is substantial, as it allows attackers to deliver victims to malware distribution sites, phishing portals designed to harvest authentication tokens, or deceptive advertisements.\nThis vulnerability is present in all versions of the Giveaways and Contests by RafflePress plugin before 1.12.27. Exploitation does not require elevated privileges or authentication, and the vulnerability is reachable over the public network via standard web interactions. The lack of validation on the URL parameter represents a significant failure in secure input handling, turning the plugin's intended functionality into a tool for malicious traffic redirection."
}