nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25033 CVE-2021-25033
MEDIUMNuclei
Noptin < 1.6.5 - Open Redirect
Record summary
CVE-2021-25033 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WordPress Newsletter Plugin – Noptin | CVE List | 1.6.5 to < 1.6.5 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMNoptin < 1.6.5 - Open RedirectCVSS 6.1
Noptin < 1.6.5 is susceptible to an open redirect vulnerability. The plugin does not validate the "to" parameter before redirecting the user to its given value, leading to an open redirect issue.
Impact
An attacker can trick users into visiting malicious websites, leading to phishing attacks.
Remediation
Update to Noptin plugin version 1.6.5 or later.
WeaknessesCWE-601
AuthorsdhiyaneshDk
Template tagscve2021cvewpwpscanwordpressredirectwp-pluginnoptinvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:noptin:noptin:*:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/c2d2384c-41b9-4aaf-b918-c1cfda58af5c https://plugins.trac.wordpress.org/changeset/2639592 https://nvd.nist.gov/vuln/detail/CVE-2021-25033 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3plugins.trac.wordpress.orgConfirmation
https://plugins.trac.wordpress.org/changeset/2639592 wpscan.com
https://wpscan.com/vulnerability/c2d2384c-41b9-4aaf-b918-c1cfda58af5c