Open Redirect Vulnerability in Solutions Ad Manager by WordPress
CVE-2025-14451

4.7MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 December 2025

What is CVE-2025-14451?

The Solutions Ad Manager plugin for WordPress is susceptible to an Open Redirect vulnerability present in all versions up to and including 1.0.0. This issue arises from inadequate validation of the redirect URL specified with the 'sam-redirect-to' parameter. As a result, unauthenticated attackers can exploit this flaw to redirect unsuspecting users to malicious websites, posing a significant security risk if users are deceived into engaging with compromised links.

Affected Version(s)

Solutions Ad Manager * <= 1.0.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ivan Cese
.