CVE-2021-25074
WebP Converter for Media < 4.0.3 - Unauthenticated Open redirect
Record summary
CVE-2021-25074 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WebP Converter for Media – Convert WebP and AVIF & Optimize Images | CVE List | 4.0.3 to < 4.0.3 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open RedirectCVSS 6.1
WordPress WebP Converter for Media < 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an open redirect issue.
Impact
An attacker can trick users into visiting a malicious website, leading to potential phishing attacks or the disclosure of sensitive information.
Remediation
Update to the latest version of the WordPress WebP Converter for Media plugin (4.0.3) or remove the plugin if not needed.
Source: ProjectDiscovery