CVE-2025-49325: WordPress Newspack Newsletters plugin <= 3.13.0 - Open Redirection Vulnerability
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Automattic Newspack Newsletters allows Phishing. This issue affects Newspack Newsletters: from n/a through 3.13.0.
Other sources
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Automattic Newspack Newsletters newspack-newsletters allows Phishing.This issue affects Newspack Newsletters: from n/a through <= 3.13.0.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49325?
CVE-2025-49325 has a moderate severity level as it enables potential phishing attacks through open redirection.
How do I fix CVE-2025-49325?
To fix CVE-2025-49325, update the Automattic Newspack Newsletters plugin to version 3.14.0 or later.
What are the potential risks associated with CVE-2025-49325?
The risks include the possibility of users being redirected to untrusted sites, leading to phishing attacks and data theft.
Which versions of Automattic Newspack Newsletters are affected by CVE-2025-49325?
Versions of Automattic Newspack Newsletters up to and including 3.13.0 are affected by CVE-2025-49325.
Who is the vendor of the affected software in CVE-2025-49325?
The vendor of the affected software in CVE-2025-49325 is Automattic, the company behind WordPress products.