Vulnerability Description
The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| English Wordpress Admin Project | English Wordpress Admin | < 1.5.2 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/af548fab-96c2-4129-b609-e24aad0b1fc4ExploitThird Party Advisory
- https://wpscan.com/vulnerability/af548fab-96c2-4129-b609-e24aad0b1fc4ExploitThird Party Advisory
FAQ
What is CVE-2021-25111?
CVE-2021-25111 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue
How severe is CVE-2021-25111?
CVE-2021-25111 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-25111?
Check the references section above for vendor advisories and patch information. Affected products include: English Wordpress Admin Project English Wordpress Admin.