WORDFENCE-33a26790-1fb8-4088-87dc-e026a28f205d
medium
📛 Threat Title
Encrypted Blog <= 0.0.6.2 - Open Redirect
Description
The Encrypted Blog plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 0.0.6.2 via the 'redirect_to' parameter in the 'encrypt_blog_form.php' file. This makes it possible for unauthenticated attackers to potentially redirect other users to arbitrary websites where they can gather sensitive information. Affected software — plugin: Encrypted Blog (affected: *-0.0.6.2). CVSS 6.1 (Medium) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: Encrypted BlogWordfence
Update to version 0.0.6.6, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.