CVE-2023-0552
Pie Register < 3.8.2.3 - Open Redirect
Record summary
CVE-2023-0552 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
The Registration Forms WordPress plugin before 3.8.2.3 does not properly validate the redirection URL when logging in and login out, leading to an Open Redirect vulnerability
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 27, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 10, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Registration FormsDefault status: unaffected | CVE List | 3.8.1.4 to < 3.8.2.3 | affected |
pie_registerBrowse genetechsolutions / pie_register | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Pie Register <3.8.2.3 - Open RedirectCVSS 5.4
WordPress Pie Register plugin before 3.8.2.3 contains an open redirect vulnerability. The plugin does not properly validate the redirection URL when logging in and login out. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
Authenticated attackers with low privileges can manipulate the redirect_to parameter during logout to redirect users to malicious sites for phishing attacks.
Remediation
Fixed in version 3.8.2.3.
Source: ProjectDiscovery