CM Registration WordPress Plugin Open Redirect Vulnerability
Vulnerability
A vulnerability allowing open redirect has been identified in the CM Registration WordPress plugin, specifically in versions through 2.5.6. The issue arises from inadequate validation of the redirect URL provided via the 'redirect_url' parameter. This flaw enables unauthenticated attackers to redirect users to potentially harmful sites, provided they can successfully persuade them to take a specific action.
Impact
Exploitation of this vulnerability could lead to open redirect, allowing attackers to send users to malicious websites.
Remediation
Users are advised to update the CM Registration WordPress plugin to version 2.5.7 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
