WordPress Solid Security Plugin <= 8.1.4 is vulnerable to Open Redirection
CVE-2023-28786

3.7LOW

Key Information:

Summary

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authentication, and Brute Force Protection.This issue affects Solid Security – Password, Two Factor Authentication, and Brute Force Protection: from n/a through 8.1.4.

Affected Version(s)

Solid Security – Password, Two Factor Authentication, and Brute Force Protection <= 8.1.4

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nlpro (Patchstack Alliance)
.