Record summary

CVE-2021-25111 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

English WordPress Admin

CVE List1.5.2 to < 1.5.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress English Admin <1.5.2 - Open RedirectCVSS 6.1

WordPress English Admin plugin before 1.5.2 contains an open redirect vulnerability. The plugin does not validate the admin_custom_language_return_url before redirecting users to it. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the execution of other malicious activities.

Remediation

Update to the latest version of the WordPress English Admin plugin (1.5.2 or higher) to fix the open redirect vulnerability.

WeaknessesCWE-601
Authorsakincibor
Template tagscve2021cveunauthwpscanwp-pluginredirectwordpresswpenglish_wordpress_admin_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:english_wordpress_admin_project:english_wordpress_admin:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2