6.1

CVE-2021-25033

Exploit

Noptin < 1.6.5 - Open Redirect

WordPress Newsletter Plugin – Noptin < 1.6.5 - Open Redirect

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue
Mögliche Gegenmaßnahme
Simple Newsletter Plugin – Noptin: Update to version 1.6.5, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NoptinNoptin SwPlatformwordpress Version < 1.6.5
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Simple Newsletter Plugin – Noptin
Version [*, 1.6.5)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.68% 0.839
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://plugins.trac.wordpress.org/changeset/2639592
Patch
Third Party Advisory
https://wpscan.com/vulnerability/c2d2384c-41b9-4aaf-b918-c1cfda58af5c
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/c5372890-72d4-482d-a7f2-04a50520c4dc
Third Party Advisory