CVE-2023-51675
WordPress Advanced Access Manager Plugin <= 6.9.18 is vulnerable to Open Redirection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18.
Vulnerabilidad de redirección de URL a un sitio que no es de confianza ("Open Redirect") en AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More. Este problema afecta a Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: desde n/a hasta el 6.9.18.
The Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.9.18. This is due to insufficient validation on the redirect url supplied via params->redirect parameter. This makes it possible for authenticated attackers (author and higher) to redirect users to potentially malicious sites if they can successfully trick them into performing an action such as logging in.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-12-21 CVE Reserved
- 2023-12-27 CVE Published
- 2024-09-09 CVE Updated
- 2024-11-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/advanced-access-manager/wordpress-advanced-access-manager-plugin-6-9-18-open-redirection-vulnerability?_s_id=cve | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Vasyltech Search vendor "Vasyltech" | Advanced Access Manager Search vendor "Vasyltech" for product "Advanced Access Manager" | < 6.9.19 Search vendor "Vasyltech" for product "Advanced Access Manager" and version " < 6.9.19" | wordpress |
Affected
|