Vulnerability Description
Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_to parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Age Verification Project | Age Verification | <= 0.4 |
| Wordpress | Wordpress | - |
Related Weaknesses (CWE)
References
- http://www.exploit-db.com/exploits/18350Exploit
- http://www.osvdb.org/82584
- http://www.securityfocus.com/bid/51357Exploit
- http://www.exploit-db.com/exploits/18350Exploit
- http://www.osvdb.org/82584
- http://www.securityfocus.com/bid/51357Exploit
FAQ
What is CVE-2012-6499?
CVE-2012-6499 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Open redirect vulnerability in age-verification.php in the Age Verification plugin 0.4 and earlier for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing a...
How severe is CVE-2012-6499?
CVE-2012-6499 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-6499?
Check the references section above for vendor advisories and patch information. Affected products include: Age Verification Project Age Verification, Wordpress Wordpress.