CVE-2021-25028
Event Tickets < 5.2.2 - Open Redirect
Record summary
CVE-2021-25028 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Event Tickets | CVE List | 5.2.2 to < 5.2.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Event Tickets < 5.2.2 - Open RedirectCVSS 6.1
WordPress Event Tickets < 5.2.2 is susceptible to an open redirect vulnerability. The plugin does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue.
Impact
Attackers can redirect users to malicious websites through the tribe_tickets_redirect_to parameter, potentially facilitating phishing attacks or malware distribution.
Remediation
Update to the latest version of the WordPress Event Tickets plugin (5.2.2 or higher) to fix the open redirect vulnerability.
Source: ProjectDiscovery