Record summary

CVE-2015-5461 has a selected CVSS score of 6.4; EIP currently links 1 Nuclei template.

Description

Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress StageShow <5.0.9 - Open RedirectCVSS 6.4

WordPress StageShow plugin before 5.0.9 contains an open redirect vulnerability in the Redirect function in stageshow_redirect.php. A remote attacker can redirect users to arbitrary web sites and conduct phishing attacks via a malicious URL in the url parameter.

Impact

An attacker can trick users into visiting a malicious website, leading to potential phishing attacks.

Remediation

Update to the latest version of the WordPress StageShow plugin (5.0.9 or higher) to fix the open redirect vulnerability.

Authors0x_Akoko
Template tagscve2015cvewpscanseclistsredirectwordpresswp-pluginstageshow_projectvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:P/A:N
CPE: cpe:2.3:a:stageshow_project:stageshow:*:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/stageshow/"

Source: ProjectDiscovery

References

7