CVE-2015-5461
WordPress StageShow <5.0.9 - Open Redirect
Record summary
CVE-2015-5461 has a selected CVSS score of 6.4; EIP currently links 1 Nuclei template.
Description
Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress StageShow <5.0.9 - Open RedirectCVSS 6.4
WordPress StageShow plugin before 5.0.9 contains an open redirect vulnerability in the Redirect function in stageshow_redirect.php. A remote attacker can redirect users to arbitrary web sites and conduct phishing attacks via a malicious URL in the url parameter.
Impact
An attacker can trick users into visiting a malicious website, leading to potential phishing attacks.
Remediation
Update to the latest version of the WordPress StageShow plugin (5.0.9 or higher) to fix the open redirect vulnerability.
Source: ProjectDiscovery