Record summary

CVE-2021-25074 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

WebP Converter for Media – Convert WebP and AVIF & Optimize Images

CVE List4.0.3 to < 4.0.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open RedirectCVSS 6.1

WordPress WebP Converter for Media < 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an open redirect issue.

Impact

An attacker can trick users into visiting a malicious website, leading to potential phishing attacks or the disclosure of sensitive information.

Remediation

Update to the latest version of the WordPress WebP Converter for Media plugin (4.0.3) or remove the plugin if not needed.

WeaknessesCWE-601
AuthorsdhiyaneshDk
Template tagscve2021cveredirectwp-pluginwebpconverterwpscanwordpresswebp_converter_for_media_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:webp_converter_for_media_project:webp_converter_for_media:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2