WP Symposium <= 13.04 - Open Redirection
2014-08-01 00:00
Charlie EriksenStrategic Overview
StatusPatched in 13.05
Affected PluginWP Symposium
Affected Version
<= 13.04CVSS6.1Medium
CVE
CVE-2013-2694Vulnerability Overview
Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the u parameter.
Technical Analysis
REMEDIATION: Update to version 13.05, or a newer patched version --- IDENTIFIER: CWE-601 (URL Redirection to Untrusted Site ('Open Redirect')) The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C