Wp Edit Password Protected WordPress Plugin Open Redirect Vulnerability
Vulnerability
An open redirect vulnerability has been identified in the Wp Edit Password Protected WordPress plugin, affecting versions prior to 1.3.5. The issue arises because the plugin fails to validate a parameter before redirecting users, allowing for potentially malicious redirection.
Impact
Exploitation of this vulnerability allows for open redirection, where users can be sent to an untrusted site under the guise of a trusted one.
Reproduction
To reproduce this vulnerability, send a POST request to 'wp-login.php' with the 'redirect_to' parameter set to the desired URL for redirection. The absence of proper validation on this parameter will result in an open redirect.
Remediation
Users are advised to update the Wp Edit Password Protected WordPress plugin to version 1.3.5 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
