Mavis HTTPS to HTTP Redirection
Mavis HTTPS to HTTP Redirection has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for Mavis HTTPS to HTTP Redirection has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Nguyen Xuan Chien. Mavis HTTPS to HTTP Redirection is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.5.20.
CVE-2025-58261Mavis HTTPS to HTTP Redirection <= 1.4.3 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
Mavis HTTPS to HTTP Redirection
Author
PressPage Entertainment Inc
This plugin was developed to solve a redirection issue when navigating from a secured checkout page back to a non-secured page (or page that you need to have as non-secured—possibly because of non-secured external links, etc.) For example, a user comes to your wordpress e-commerce site, locates an item, then navigates to your secured checkout page. Now the customer, realizes there is something else they need, and instead of clicking a Continue Shopping link, then click a top category link. Since the customer is in a secured session, wordpress put the secured protocol on all the links including that category. Now the customer navigates to that category, but they are still in a secured page session. Now this category page is displaying improperly because of some external links that did not translate properly into the secured session. Customer is now upset, thinking that the site design demonstrates the level of incompetence of the shop owner and questions the shop owner’s integrity to fulfill the customer’s order, so the customer in a behavior of discuss, rapidly leaves the shop owner’s site and that customer becomes a non-customer! This plugin resolves this issue by redirecting all non specified checkout (and other non-secured pages) back to a non-secured page counterpart. Credits We make honorable mention to anyone who helps make Mavis HTTPS to HTTP Redirect a better plugin! Contact Support is provided at https://github.com/pingleware/mavis-https-to-http-redirect/issues. You will require a free account on github.com Please contact presspage.entertainment@gmail.com or visit the above forum with questions, comments, or requests.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C