PT-2023-10283 · WordPress · Icons For Features Plugin
Published
2023-04-30
·
Updated
2024-05-17
·
CVE-2015-10104
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Icons for Features Plugin version 1.0.0
Description
A problematic issue has been found in the Icons for Features Plugin on WordPress, affecting some unknown functionality of the file classes/class-icons-for-features-admin.php. The manipulation of the
redirect url argument leads to open redirect. The attack may be launched remotely. Upgrading to version 1.0.1 is able to address this issue.Recommendations
For Icons for Features Plugin version 1.0.0, upgrade to version 1.0.1 to address the issue. As a temporary workaround, consider restricting the manipulation of the
redirect url argument to minimize the risk of exploitation.Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Icons For Features Plugin