The Events Calendar < 4.1.1.1 - Open Redirect

2016-04-25 00:00
Paul Mynarsky

Strategic Overview

Status
Patched in 4.1.1.1
Affected PluginThe Events Calendar
Affected Version<= 4.1.1
CVSS4.7Medium
CVEN/A
View all The Events Calendar vulnerabilities

Vulnerability Overview

The Events Calendar plugin for WordPress is vulnerable to an open redirect vulnerability in versions before 4.1.1.1. This allows attackers to redirect victims to an untrusted site via a crafted link on a vulnerable trusted site.

Technical Analysis

REMEDIATION: Update to version 4.1.1.1, or a newer patched version --- IDENTIFIER: CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')) The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C