PT-2023-10292 · WordPress · Woosidebars Plugin
Jeffikus
·
Published
2023-06-05
·
Updated
2024-05-17
·
CVE-2015-10114
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WooSidebars Plugin versions up to 1.4.1
Description
A problematic issue has been found in the WooSidebars Plugin on WordPress, affecting the function
enable custom post sidebars of the file classes/class-woo-sidebars.php. The manipulation of the argument sendback leads to open redirect. The attack may be launched remotely.Recommendations
For WooSidebars Plugin versions up to 1.4.1, upgrade to version 1.4.2 to address this issue. As a temporary workaround, consider disabling the
enable custom post sidebars function until the patch is applied. Restrict access to the classes/class-woo-sidebars.php file to minimize the risk of exploitation. Avoid using the argument sendback in the affected function until the issue is resolved.Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woosidebars Plugin