Record summary

CVE-2021-25033 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

WordPress Newsletter Plugin – Noptin

CVE List1.6.5 to < 1.6.5affected

Nuclei templates

1
ProjectDiscoveryMEDIUMNoptin < 1.6.5 - Open RedirectCVSS 6.1

Noptin < 1.6.5 is susceptible to an open redirect vulnerability. The plugin does not validate the "to" parameter before redirecting the user to its given value, leading to an open redirect issue.

Impact

An attacker can trick users into visiting malicious websites, leading to phishing attacks.

Remediation

Update to Noptin plugin version 1.6.5 or later.

WeaknessesCWE-601
AuthorsdhiyaneshDk
Template tagscve2021cvewpwpscanwordpressredirectwp-pluginnoptinvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:noptin:noptin:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3