CVE-2023-27624
WordPress Redirect After Login Plugin <= 0.1.9 is vulnerable to Cross Site Scripting (XSS)
Record summary
CVE-2023-27624 has a selected CVSS score of 5.9 (medium); EIP currently links 1 Nuclei template.
Description
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 versions.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 10, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Redirect After LoginBrowse Marcelotorres / Redirect After LoginDefault status: unaffected | CVE List | Through 0.1.9 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Redirect After Login <= 0.1.9 - Admin Stored XSSCVSS 5.9
Marcelotorres Redirect After Login plugin <= 0.1.9 contains a stored cross-site scripting caused by insufficient sanitization in the login redirect parameter, letting attackers execute scripts in the context of the affected site, exploit requires admin privileges.
Impact
Attackers can execute malicious scripts in the context of the affected site, potentially leading to session hijacking or defacement.
Remediation
Update to the latest version of the plugin where the vulnerability is fixed.
Source: ProjectDiscovery