Junglewise Threat Intelligence

CVE-2026-7561: Tm WordPress Redirection CSRF in tm-redirect.php

CVE-2026-7561 · Severity: medium · CVSS 6.1 · Published 2026-05-12

Executive brief

The Tm – WordPress Redirection plugin for WordPress is vulnerable to a security flaw that allows attackers to trick site administrators into performing unintended actions. By convincing an administrator to click a malicious link, an attacker can change plugin settings or inject harmful scripts into the website. This could lead to unauthorized site modifications or the compromise of visitor data.

Technical details

The Tm – WordPress Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to and including 1.2. The vulnerability stems from missing or incorrect nonce validation on certain functions within the tm-redirect.php file. An unauthenticated attacker can exploit this by crafting a malicious request and using social engineering to trick a logged-in administrator into executing it (e.g., via a phishing link). Successful exploitation allows the attacker to modify plugin settings and perform Stored Cross-Site Scripting (XSS) by injecting malicious scripts into the site's configuration.

Affected products

  • Tm Tm – WordPress Redirection up to, and including, 1.2

Timeline

  • 2026-05-12: advisory: Initial disclosure by Wordfence and NVD publication.

References