Record summary

CVE-2024-3032 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Themify Builder WordPress plugin before 7.5.8 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 17, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Themify Builder

Default status: unaffected

CVE ListBefore 7.5.8affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Themify Builder < 7.5.8 - Open RedirectCVSS 6.1

The Themify Builder WordPress plugin before version 7.5.8 contains an open redirect vulnerability. The plugin does not validate the tb_redirect_fail parameter before redirecting users to its value, which could allow attackers to redirect users to malicious websites.

Impact

Attackers can redirect users to malicious websites, potentially leading to phishing attacks or credential theft.

Remediation

Update Themify Builder to version 7.5.8 or later.

WeaknessesCWE-601
Authorsritikchaddha
Template tagscvecve2024wpwordpresswp-pluginredirectthemify-buildervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:themify:builder:*:*:*:*:-:wordpress:*:*
FOFA: body="wp-content/plugins/themify-builder/"

Source: ProjectDiscovery

References

2