Description
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-11945 | The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:49:14.591Z
Reserved: 2021-01-14T00:00:00.000Z
Link: CVE-2021-25033
No data.
Status : Modified
Published: 2022-02-14T12:15:15.003
Modified: 2024-11-21T05:54:13.480
Link: CVE-2021-25033
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD