CVE-2021-25111
English WordPress Admin < 1.5.2 - Unauthenticated Open Redirect
Record summary
CVE-2021-25111 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
English WordPress Admin | CVE List | 1.5.2 to < 1.5.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress English Admin <1.5.2 - Open RedirectCVSS 6.1
WordPress English Admin plugin before 1.5.2 contains an open redirect vulnerability. The plugin does not validate the admin_custom_language_return_url before redirecting users to it. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the execution of other malicious activities.
Remediation
Update to the latest version of the WordPress English Admin plugin (1.5.2 or higher) to fix the open redirect vulnerability.
Source: ProjectDiscovery