.. / CVE-2021-25111

Exploit for WordPress English Admin <1.5.2 - Open Redirect (CVE-2021-25111)

Description:

WordPress English Admin plugin before 1.5.2 contains an open redirect vulnerability. The plugin does not validate the admin_custom_language_return_url before redirecting users to it. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Nuclei Template

View the template here CVE-2021-25111.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-25111.yaml
Copy

References:

https://wpscan.com/vulnerability/af548fab-96c2-4129-b609-e24aad0b1fc4
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2021-25111