Noptin < 1.6.5 - Open Redirect
CVE-2021-25033
6.1MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 14 February 2022
What is CVE-2021-25033?
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue
Affected Version(s)
WordPress Newsletter Plugin – Noptin 1.6.5