6.4
CVE-2015-5461
- EPSS 6.28%
- Veröffentlicht 08.07.2015 16:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
StageShow < 5.0.9 - Open Redirect
Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
Mögliche Gegenmaßnahme
StageShow: Update to version 5.0.9, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Stageshow Project ≫ Stageshow SwPlatformwordpress Version <= 5.08
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
StageShow
Version
[*, 5.0.9)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 6.28% | 0.927 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
http://packetstormsecurity.com/files/132553/WordPress-StageShow-5.0.8-Open-Redirect.html
http://seclists.org/fulldisclosure/2015/Jul/27
http://www.securityfocus.com/bid/75552
https://plugins.trac.wordpress.org/changeset/1165310/
https://wordpress.org/plugins/stageshow/changelog/
https://wpvulndb.com/vulnerabilities/8073
https://www.wordfence.com/threat-intel/vulnerabilities/id/bbc8ccc1-7b72-44fb-8bf5-e7cb46081ed5