PT-2025-41647 · WordPress · Cm Registration

Jonas Benjamin Friedli

·

Publicado

2025-10-11

·

Atualizado

2025-10-11

·

CVE-2025-11167

CVSS v3.1

4.7

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress versions through 2.5.6
Description The software is susceptible to an Open Redirect issue because of inadequate validation of the redirect URL provided through the redirect url parameter. This allows unauthenticated attackers to redirect users to potentially harmful websites if they can trick users into taking an action.
Recommendations Update the CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress to a version later than 2.5.6.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-11167

Produtos afetados

Cm Registration