WordPress AcyMailing plugin before 7.5.0 contains an open redirect vulnerability due to improper sanitization of the redirect parameter. An attacker turning the request from POST to GET can craft a link containing a potentially malicious landing page and send it to the user.
View the template here CVE-2021-24288.yaml
References:
https://github.com/ARPSyndicate/cvemon