Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-81342

Опубликовано: 29 авг. 2026
Источник: nvd
CVSS3: 4.7
EPSS Низкий

Описание

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

EPSS

Процентиль: 7%
0.00171
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.7
github
23 дня назад

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

EPSS

Процентиль: 7%
0.00171
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-601