CVE-2012-6499
WordPress Plugin Age Verification 0.4 - Open Redirect
Record summary
CVE-2012-6499 has a selected CVSS score of 5.8; EIP currently links 2 catalogued exploits and 1 Nuclei template.
Description
Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBWordPress Plugin Age Verification 0.4 - Open RedirectExploitDB exploitby Gianluca BrindisiNot analyzed1 file
ExploitDBWordPress Plugin Age Verification 0.4 - 'redirect_to' Open RedirectionExploitDB exploitby Gianluca BrindisiNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Plugin Age Verification v0.4 - Open RedirectCVSS 5.8
Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.
Remediation
Update to the latest version of the WordPress Plugin Age Verification or remove the plugin if not needed.
Source: ProjectDiscovery