CVE-2023-28786 LOW

CVE-2023-28786: WordPress Solid Security Plugin <= 8.1.4 is vulnerable to Open Redirection

Vendor Solidwp
Product Solid Security – Password, Two Factor Authentication, and Brute Force Protection
Weakness CWE-601 · Open redirect
Published December 29, 2023
Last update April 28, 2026

CVSS base score

3.7/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SolidWP Solid Security – Password, Two Factor Authentication, and Brute Force Protection.This issue affects Solid Security – Password, Two Factor Authentication, and Brute Force Protection: from n/a through 8.1.4.

Explanation of Vulnerability in Simple Terms

02Summary

Solid Security versions up to 8.1.4 contain an open redirect vulnerability that allows an attacker to craft a malicious link redirecting users to an external website. The vulnerability requires high attack complexity but no authentication. While the integrity impact is low, this can be used in phishing attacks to trick users into visiting attacker-controlled sites.

What an attacker can do

03Attacker Capabilities

Craft a malicious link that redirects users to an external website when clicked.

Potential impact on your site

04Site Impact

Users could be redirected to phishing or malware sites, damaging trust in your site and potentially compromising user credentials.

Conditions required to exploit

05Prerequisites

Attacker must craft a specially designed URL; no authentication required. User must click the link.

Key dates

06Disclosure timeline

December 29, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE