CVE-2023-5610
MEDIUMSeraphinite Accelerator < 2.2.29 - Authenticated Open Redirect
Title source: llmDescription
The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect
References (1)
Core 1
Core References
Exploit, Product, Third Party Advisory exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/e880a9fb-b089-4f98-9781-7d946f22777e
Scores
CVSS v3
5.4
EPSS
0.0037
EPSS Percentile
28.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-601
Status
published
Products (1)
s-sols/seraphinite_accelerator
< 2.2.29
Published
Nov 20, 2023
Tracked Since
Feb 18, 2026