CVE-2021-38343 MEDIUM

CVE-2021-38343: Nested Pages <= 3.1.15 Open Redirect

Vendor Kyle Phillips
Product Nested Pages
Weakness CWE-601 · Open redirect
Published August 30, 2021
Last update September 17, 2024

CVSS base score

4.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npBulkActions`, `npBulkEdit`, `npListingSort`, and `npCategoryFilter` `admin_post` actions.

Key dates

02Disclosure timeline

August 30, 2021 CVE published
September 17, 2024 Record updated