CVE-2007-1599: Medium severity WordPress vulnerability
Published Mar 22, 2007
·Updated
wp-login.php in WordPress allows remote attackers to redirect authenticated users to other websites and potentially obtain sensitive information via the redirectto parameter.
Affected Software
1 affected component
WordPress=2.1.2
Event History
Mar 22, 2007
CVE Published
11:19 PM
Mar 23, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1599?
CVE-2007-1599 has a medium severity level, as it allows for potential phishing attacks and information exposure.
2
How do I fix CVE-2007-1599?
To fix CVE-2007-1599, upgrade to a patched version of WordPress that addresses the redirect_to parameter vulnerability.
3
What does CVE-2007-1599 affect?
CVE-2007-1599 specifically affects WordPress version 2.1.2.
4
Can CVE-2007-1599 be exploited without user interaction?
CVE-2007-1599 requires authenticated users to be tricked into clicking a malicious link, making user interaction necessary for exploitation.
5
What are the potential consequences of CVE-2007-1599?
Exploiting CVE-2007-1599 can lead to unauthorized redirection of users, resulting in possible exposure of sensitive information.