CVE-2023-6389

CVE-2023-6389: WordPress Toolbar <= 2.2.6 - Open Redirect

Vendor Unknown
Product WordPress Toolbar
Published January 29, 2024
Last update June 20, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

Key dates

02Disclosure timeline

January 29, 2024 CVE published
June 20, 2025 Record updated