ZeroHour

CVE-2021-25074

PoC
CVSS 3.1
6.1 medium
EPSS
2%p81
Published
()
Modified
Description

The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

Vendors
webp converter for media project
Products
webp converter for media
Ecosystems
WordPress
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.