#VU8512 Open redirect in WordPress - CVE-2017-14725
Published: September 20, 2017 / Updated: October 15, 2017
WordPress
WordPress.ORG
Description
The vulnerability allows a remote attacker to perform spoofing attacks.
The vulnerability exists due to insufficient validation of user-supplied data when performing redirects to external websites on the user and term edit screens. A remote attacker can trick the victim to follow a specially crafted link and perform a psoofing attack.