CVE-2021-24406: wpForo Forum < 1.9.7 - Open Redirect
The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirectto parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24406.
What is the severity rating of CVE-2021-24406?
CVE-2021-24406 has a severity rating of medium (6.1).
Which software version is affected by CVE-2021-24406?
The wpForo Forum WordPress plugin version before 1.9.7 is affected by CVE-2021-24406.
What is the issue in wpForo Forum WordPress plugin version before 1.9.7?
The login form of the wpForo Forum plugin before 1.9.7 does not validate the redirect_to parameter, allowing an open redirect issue after a successful login.
How can an attacker exploit this vulnerability in wpForo Forum WordPress plugin version before 1.9.7?
An attacker can induce a user to use a login URL redirecting to a website under their control.