Open Redirect Vulnerability in Aculect AI Companion by Mehul Gohil
CVE-2026-39600

4.7MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 October 2026

What is CVE-2026-39600?

The Aculect AI Companion, developed by Mehul Gohil, is impacted by a vulnerability that allows attackers to manipulate URL redirections to untrusted sites. This unvalidated redirect flaw creates an opportunity for phishing attacks, potentially compromising user data and security. The vulnerability affects versions from n/a up to 0.8.1, making it essential for users to verify their installations and promptly apply any security updates to mitigate risks.

Affected Version(s)

Aculect AI Companion 0 <= 0.8.1

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.