Record summary

CVE-2017-14725 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

Before version 4.8.2, WordPress was susceptible to an open redirect attack in wp-admin/edit-tag-form.php and wp-admin/user-edit.php.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress < 4.8.2 - Authenticated Open RedirectCVSS 5.4

WordPress versions before 4.8.2 contain an open redirect caused by improper validation in wp-admin/edit-tag-form.php and wp-admin/user-edit.php, letting attackers redirect users to malicious sites, exploit requires access to admin interface.

Impact

Attackers can redirect authenticated users to malicious sites, potentially leading to phishing or malware distribution.

Remediation

Update to WordPress 4.8.2 or later.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2017wpscanwordpressredirectauthenticated
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*
Shodan: http.component:"wordpress"
Shodan: cpe:"cpe:2.3:a:wordpress:wordpress"
FOFA: body="oembed" && body="wp-"

Source: ProjectDiscovery

References

7