CVE-2021-25111

CVE-2021-25111: English WordPress Admin < 1.5.2 - Unauthenticated Open Redirect

Vendor Unknown
Product English WordPress Admin
Weakness CWE-601 · Open redirect
Published April 25, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue

Key dates

02Disclosure timeline

April 25, 2022 CVE published
August 3, 2024 Record updated