What the vulnerability does
01Description
A vulnerability, which was classified as problematic, has been found in WooSidebars Plugin up to 1.4.1 on WordPress. Affected by this issue is the function enable_custom_post_sidebars of the file classes/class-woo-sidebars.php. The manipulation of the argument sendback leads to open redirect. The attack may be launched remotely. Upgrading to version 1.4.2 is able to address this issue. The patch is identified as 1ac6d6ac26e185673f95fc1ccc56a392169ba601. It is recommended to upgrade the affected component. VDB-230654 is the identifier assigned to this vulnerability.
Explanation of Vulnerability in Simple Terms
02Summary
The WooSidebars plugin contains an open redirect vulnerability that allows an attacker to redirect users to an external website. The vulnerability requires user interaction—the victim must click a malicious link. The redirect does not expose sensitive data but can be used for phishing or social engineering attacks against your site's visitors.
What an attacker can do
03Attacker Capabilities
Redirect site visitors to an external website via a crafted link.
Potential impact on your site
04Site Impact
Visitors can be redirected away from your site to phishing or malware sites, damaging trust.
Conditions required to exploit
05Prerequisites
Victim must click a malicious link; no authentication required.
Key dates
06Disclosure timeline
June 5, 2023
CVE published
August 6, 2024
Record updated