Record summary

CVE-2023-0552 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 27, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Registration Forms

Default status: unaffected

CVE List3.8.1.4 to < 3.8.2.3affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Pie Register <3.8.2.3 - Open RedirectCVSS 5.4

WordPress Pie Register plugin before 3.8.2.3 contains an open redirect vulnerability. The plugin does not properly validate the redirection URL when logging in and login out. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Authenticated attackers with low privileges can manipulate the redirect_to parameter during logout to redirect users to malicious sites for phishing attacks.

Remediation

Fixed in version 3.8.2.3.

WeaknessesCWE-601
Authorsr3Y3r53
Template tagscve2023cveredirectpiepie-registerwpscangenetechsolutionswordpressvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:genetechsolutions:pie_register:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2