PT-2025-41647 · WordPress · Cm Registration

Jonas Benjamin Friedli

·

Published

2025-10-11

·

Updated

2025-10-11

·

CVE-2025-11167

CVSS v3.1

4.7

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress versions through 2.5.6
Description The software is susceptible to an Open Redirect issue because of inadequate validation of the redirect URL provided through the redirect url parameter. This allows unauthenticated attackers to redirect users to potentially harmful websites if they can trick users into taking an action.
Recommendations Update the CM Registration – Tailored tool for seamless login and invitation-based registrations plugin for WordPress to a version later than 2.5.6.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-11167

Affected Products

Cm Registration