PoC Index

CVE-2021-25033

MEDIUM 6.1EPSS 2.3%

The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
2.30% chance of exploitation in the next 30 days, 82th percentile
Nuclei
medium · CWE-601
Published
2022-02-14
Updated
2024-08-03

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related