Record summary

CVE-2012-6499 has a selected CVSS score of 5.8; EIP currently links 2 catalogued exploits and 1 Nuclei template.

Description

Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2
Nuclei templates
1

Proofs of concept

2

Catalogued exploits

ExploitDBWordPress Plugin Age Verification 0.4 - Open RedirectExploitDB exploitby Gianluca BrindisiNot analyzed1 file
ExploitDB

PoC details
ExploitDBWordPress Plugin Age Verification 0.4 - 'redirect_to' Open RedirectionExploitDB exploitby Gianluca BrindisiNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Plugin Age Verification v0.4 - Open RedirectCVSS 5.8

Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.

Remediation

Update to the latest version of the WordPress Plugin Age Verification or remove the plugin if not needed.

WeaknessesCWE-20
Authorsctflearner
Template tagscvecve2012wordpresswpwp-pluginredirectage-verificationage_verification_projectvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:N
CPE: cpe:2.3:a:age_verification_project:age_verification:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4