CVE-2024-3032

MEDIUM NUCLEI

Themify Builder < 7.5.8 - Open Redirect via Unvalidated Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-3032 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

Nuclei Templates (1)

WordPress Themify Builder < 7.5.8 - Open Redirect
MEDIUMby ritikchaddha
FOFA: body="wp-content/plugins/themify-builder/"

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/d130a60c-c36b-4994-9b0e-e52cd7f99387/

Scores

CVSS v3 6.1
EPSS 0.0082
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
themify/builder < 7.5.8
Published Jun 13, 2024
Tracked Since Feb 18, 2026