WPFactory Scheduled & Automatic Order Status Controller for WooCommerce Open Redirect Vulnerability

Vulnerability

A URL redirection vulnerability allowing open redirects has been identified in the WPFactory Scheduled & Automatic Order Status Controller for WooCommerce, affecting versions through 3.7.1. This vulnerability could be exploited for phishing attacks by redirecting users to untrusted sites.

Impact

Exploitation of this vulnerability could lead to phishing incidents, as users might be tricked into visiting malicious sites under the guise of legitimate ones.

Remediation

Users of the WPFactory Scheduled & Automatic Order Status Controller for WooCommerce should update to version 3.7.2 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.2
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.