PT-2022-9657 · WordPress · All-In-One-Wp-Security-And-Firewall
Jrxnm
+1
·
Published
2022-05-02
·
Updated
2022-05-10
·
CVE-2021-25102
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
All In One WP Security & Firewall WordPress plugin versions prior to 4.4.11
Description
The issue arises from the lack of validation, sanitization, and escaping of the
redirect to parameter, which can lead to Arbitrary Redirect and Cross-Site Scripting issues when the Rename Login Page feature is active. Exploitation requires knowledge of the Login Page URL value, which is considered hard to guess, thereby reducing the risk.Recommendations
For versions prior to 4.4.11, update to version 4.4.11 or later to resolve the issue. As a temporary workaround, consider disabling the Rename Login Page feature until a patch is available. Restrict access to the login page to minimize the risk of exploitation. Avoid using the
redirect to parameter in the affected plugin until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
All-In-One-Wp-Security-And-Firewall