ZeroHour

CVE-2021-25033

PoC
CVSS 3.1
6.1 medium
EPSS
2%p82
Published
()
Modified
Description

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

Vendors
noptin
Products
noptin
Ecosystems
WordPress
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.