Wp Edit Password Protected WordPress Plugin Open Redirect Vulnerability

Vulnerability

An open redirect vulnerability has been identified in the Wp Edit Password Protected WordPress plugin, affecting versions prior to 1.3.5. The issue arises because the plugin fails to validate a parameter before redirecting users, allowing for potentially malicious redirection.

Impact

Exploitation of this vulnerability allows for open redirection, where users can be sent to an untrusted site under the guise of a trusted one.

Reproduction

To reproduce this vulnerability, send a POST request to 'wp-login.php' with the 'redirect_to' parameter set to the desired URL for redirection. The absence of proper validation on this parameter will result in an open redirect.

Remediation

Users are advised to update the Wp Edit Password Protected WordPress plugin to version 1.3.5 or later.

Added: Sep 11, 2025, 6:17 AM
Updated: Sep 11, 2025, 6:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
0.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.