What the vulnerability does
01Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership After Login Redirection simple-membership-after-login-redirection.This issue affects Simple Membership After Login Redirection: from n/a through <= 1.6.
Explanation of Vulnerability in Simple Terms
02Summary
The Simple Membership After Login Redirection plugin for WordPress contains an open redirect vulnerability in versions 1.6 and earlier. An attacker can craft a malicious link that redirects authenticated users to an external website after login. The vulnerability requires user interaction—the victim must click the attacker's link—but can be used for phishing or credential harvesting attacks.
What an attacker can do
03Attacker Capabilities
Redirect logged-in users to a malicious external website via a crafted link.
Potential impact on your site
04Site Impact
Users can be redirected to phishing sites or malware after logging in, potentially compromising credentials or devices.
Conditions required to exploit
05Prerequisites
User must click an attacker-supplied link and complete login.
Key dates
06Disclosure timeline
October 10, 2024
CVE published
April 28, 2026
Record updated