Wordpress Alert: Malicious redirects through open-redirect flaws

A site link forwards visitors to an attacker-chosen destination. The trusted domain can be used in phishing links.

What it looks like

A site link forwards visitors to an attacker-chosen destination.

Why it matters

The trusted domain can be used in phishing links.

What to check

Review redirect parameters and allow only approved destinations.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP unvalidated redirects guidance.