CVE-2018-16174: Medium severity thimpress learnpress vulnerability
Published Jan 9, 2019
·Updated
Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Affected Software
1 affected component
thimpress Learnpress Wordpress<3.1.0
Event History
Jan 9, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-16174?
CVE-2018-16174 is an open redirect vulnerability in LearnPress prior to version 3.1.0.
2
How does CVE-2018-16174 impact LearnPress?
CVE-2018-16174 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks.
3
What is the severity of CVE-2018-16174?
The severity of CVE-2018-16174 is medium with a CVSS score of 6.1.
4
Which version of LearnPress is affected by CVE-2018-16174?
LearnPress versions prior to 3.1.0 are affected by CVE-2018-16174.
5
How can I fix CVE-2018-16174?
To fix CVE-2018-16174, update LearnPress to version 3.1.0 or later.