CVE-2025-39599: WordPress Listdom plugin <= 4.0.0 - Open Redirection Vulnerability
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Webilia Inc. Listdom allows Phishing. This issue affects Listdom: from n/a through 4.0.0.
Other sources
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Webilia Inc. Listdom listdom allows Phishing.This issue affects Listdom: from n/a through <= 4.0.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39599?
CVE-2025-39599 is considered to have a medium severity due to its potential for allowing phishing attacks.
How do I fix CVE-2025-39599?
To fix CVE-2025-39599, upgrade Webilia Listdom to version 4.0.1 or later.
What are the risks of CVE-2025-39599?
The primary risk of CVE-2025-39599 is the potential for attackers to redirect users to untrusted sites for phishing purposes.
Which versions of Listdom are affected by CVE-2025-39599?
CVE-2025-39599 affects Listdom versions up to and including 4.0.0.
Is CVE-2025-39599 exploitable on all installations of Listdom?
Yes, CVE-2025-39599 is exploitable on all installations of Listdom version 4.0.0 and below.