Music Store – WordPress eCommerce < 1.0.15 - Open Redirect
Strategic Overview
- Status
- Patched in 1.0.15
- Affected Plugin
- Music Store – WordPress eCommerce
- Affected Version
< 1.0.15- CVSS
- 7.2High
- Weakness type
- CWE-601 · URL Redirection to Untrusted Site ('Open Redirect')
- CVE
CVE pending
At a glance
This record tracks a high-severity URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Music Store WordPress plugin, affecting versions < 1.0.15. It carries a CVSS score of 7.2 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 1.0.15; sites on affected versions should update now. Disclosed July 2015, reported by Nitin Venkatesh.
Vulnerability Overview
An open redirect in the Music Store – WordPress eCommerce plugin before 1.0.15 for WordPress allows attackers to redirect a user by adding HTTP referer to ms-core/ms-submit.php.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
Reaching this weakness in Music Store < 1.0.15 takes a caller who can reach the endpoint. An open redirect is a page that takes a destination from the request and sends the browser there without checking that the destination belongs to the site.
A link that starts on a trusted domain finishes on an attacker's, which is what makes phishing and consent-screen abuse credible to the person clicking it. For Music Store the fix is 1.0.15: builds < 1.0.15 are affected, anything from 1.0.15 onward is not.
Remediation
Update to version 1.0.15, or a newer patched version
How does WordSec protect against this?
The attempt arrives as an ordinary request to Music Store: WordSec's web application firewall inspects request payloads before WordPress loads them. None of that substitutes for the fix: Music Store 1.0.15 closes this, and updating the plugin is the step that ends it.
- Firewall
- Alerts
External References
Related records
Other vulnerabilities in Music Store – WordPress eCommerce
- 9.1CVE-2024-36082: Music Store - WordPress eCommerce SQL Injection
CVE-2024-36082 - 7.5CVE-2026-82304: Music Store – WordPress eCommerce SQL Injection
CVE-2026-82304 - 6.1CVE-2025-24626: Music Store – WordPress eCommerce Reflected XSS
CVE-2025-24626 - 6.1CVE-2016-10992: Music Store <= 1.0.41 Cross-Site Scripting
CVE-2016-10992
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C