First published: Mon Apr 25 2022(Updated: )
The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Admin | <1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25111 is considered a medium severity vulnerability due to its open redirect issue.
To fix CVE-2021-25111, update the English WordPress Admin plugin to version 1.5.2 or higher, where the vulnerability is patched.
CVE-2021-25111 is classified as an open redirect vulnerability impacting the English WordPress Admin plugin.
Versions prior to 1.5.2 of the English WordPress Admin plugin are affected by CVE-2021-25111.
Yes, CVE-2021-25111 can potentially lead to phishing attacks through the open redirect, making it a security concern.