CM Registration WordPress Plugin Open Redirect Vulnerability

Vulnerability

A vulnerability allowing open redirect has been identified in the CM Registration WordPress plugin, specifically in versions through 2.5.6. The issue arises from inadequate validation of the redirect URL provided via the 'redirect_url' parameter. This flaw enables unauthenticated attackers to redirect users to potentially harmful sites, provided they can successfully persuade them to take a specific action.

Impact

Exploitation of this vulnerability could lead to open redirect, allowing attackers to send users to malicious websites.

Remediation

Users are advised to update the CM Registration WordPress plugin to version 2.5.7 or a newer patched version.

Added: Oct 11, 2025, 9:26 AM
Updated: Oct 11, 2025, 9:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.0
remediation
7.7
relevance
0.7
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.