PT-2022-9630 · WordPress · Webp Converter For Media
Krzysztof Zając
·
Published
2022-01-24
·
Updated
2022-01-28
·
CVE-2021-25074
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WebP Converter for Media WordPress plugin versions prior to 4.0.3
Description
The issue arises from a file named
passthru.php that fails to validate the src parameter before redirecting the user to it, resulting in an Open Redirect issue.Recommendations
For versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
passthru.php file to minimize the risk of exploitation.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webp Converter For Media