PT-2023-10292 · WordPress · Woosidebars Plugin

·

CVE-2015-10114

·

Published

2023-06-05

·

Updated

2024-05-17

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WooSidebars Plugin versions up to 1.4.1
Description A problematic issue has been found in the WooSidebars Plugin on WordPress, affecting the function enable custom post sidebars of the file classes/class-woo-sidebars.php. The manipulation of the argument sendback leads to open redirect. The attack may be launched remotely.
Recommendations For WooSidebars Plugin versions up to 1.4.1, upgrade to version 1.4.2 to address this issue. As a temporary workaround, consider disabling the enable custom post sidebars function until the patch is applied. Restrict access to the classes/class-woo-sidebars.php file to minimize the risk of exploitation. Avoid using the argument sendback in the affected function until the issue is resolved.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-10114

Affected Products

Woosidebars Plugin