WordPress English Admin plugin before 1.5.2 contains an open redirect vulnerability. The plugin does not validate the admin_custom_language_return_url before redirecting users to it. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
View the template here CVE-2021-25111.yaml
References:
https://wpscan.com/vulnerability/af548fab-96c2-4129-b609-e24aad0b1fc4