PT-2023-10292 · WordPress · Woosidebars Plugin

Jeffikus

·

Published

2023-06-05

·

Updated

2024-05-17

·

CVE-2015-10114

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WooSidebars Plugin versions up to 1.4.1
Description A problematic issue has been found in the WooSidebars Plugin on WordPress, affecting the function enable custom post sidebars of the file classes/class-woo-sidebars.php. The manipulation of the argument sendback leads to open redirect. The attack may be launched remotely.
Recommendations For WooSidebars Plugin versions up to 1.4.1, upgrade to version 1.4.2 to address this issue. As a temporary workaround, consider disabling the enable custom post sidebars function until the patch is applied. Restrict access to the classes/class-woo-sidebars.php file to minimize the risk of exploitation. Avoid using the argument sendback in the affected function until the issue is resolved.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2015-10114

Affected Products

Woosidebars Plugin