Record summary

CVE-2021-25028 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Event Tickets WordPress plugin before 5.2.2 does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Event Tickets

CVE List5.2.2 to < 5.2.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Event Tickets < 5.2.2 - Open RedirectCVSS 6.1

WordPress Event Tickets < 5.2.2 is susceptible to an open redirect vulnerability. The plugin does not validate the tribe_tickets_redirect_to parameter before redirecting the user to the given value, leading to an arbitrary redirect issue.

Impact

Attackers can redirect users to malicious websites through the tribe_tickets_redirect_to parameter, potentially facilitating phishing attacks or malware distribution.

Remediation

Update to the latest version of the WordPress Event Tickets plugin (5.2.2 or higher) to fix the open redirect vulnerability.

WeaknessesCWE-601
AuthorsdhiyaneshDk
Template tagscve2021cvewordpressredirectwp-plugineventticketswpscantrivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:tri:event_tickets:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2