CVE-2024-3032
Themify Builder < 7.5.8 - Open Redirect
Record summary
CVE-2024-3032 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 17, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Themify BuilderDefault status: unaffected | CVE List | Before 7.5.8 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Themify Builder < 7.5.8 - Open RedirectCVSS 6.1
The Themify Builder WordPress plugin before version 7.5.8 contains an open redirect vulnerability. The plugin does not validate the tb_redirect_fail parameter before redirecting users to its value, which could allow attackers to redirect users to malicious websites.
Impact
Attackers can redirect users to malicious websites, potentially leading to phishing attacks or credential theft.
Remediation
Update Themify Builder to version 7.5.8 or later.
Source: ProjectDiscovery