CVE-2021-25033: Noptin < 1.6.5 - Open Redirect
Published Feb 14, 2022
·Updated
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue
Affected Software
1 affected component
Noptin Noptin Wordpress<1.6.5
Remediation
Patch Available
Event History
Feb 14, 2022
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-25033?
CVE-2021-25033 is a vulnerability in the WordPress Newsletter Plugin WordPress plugin before version 1.6.5 that allows for an open redirect issue.
2
How severe is CVE-2021-25033?
CVE-2021-25033 has a severity value of 6.1, which is considered medium.
3
How does CVE-2021-25033 affect the Noptin Noptin plugin?
CVE-2021-25033 affects the Noptin Noptin plugin version up to 1.6.5.
4
What is the Common Weakness Enumeration (CWE) for CVE-2021-25033?
CVE-2021-25033 is associated with CWE-601.
5
How can I fix the CVE-2021-25033 vulnerability?
To fix the CVE-2021-25033 vulnerability, update the WordPress Newsletter Plugin to version 1.6.5 or later.