CVE-2024-13888
Last modified
CVE-2024-13888 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This is due to insufficient validation on the redirect URL supplied via the 'redirect' parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amauri | Wpmobile.App | < 11.57 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-13888?
How severe is CVE-2024-13888?
How do I fix CVE-2024-13888?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13881The Link My Posts WordPress plugin through 1.0 does not sani…7.1
- CVE-2024-13882The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 &…8.8
- CVE-2024-13883The WPUpper Share Buttons plugin for WordPress is vulnerable…4.3
- CVE-2024-13884The Limit Bio WordPress plugin through 1.0 does not sanitise…7.1
- CVE-2024-13885The WP e-Customers Beta WordPress plugin through 0.0.1 does …7.1
- CVE-2024-13887The Business Directory Plugin – Easy Listing Directories for…5.3
- CVE-2024-13889The WordPress Importer plugin for WordPress is vulnerable to…7.2
- CVE-2024-1389The Paid Membership Subscriptions – Effortless Memberships, …5.3
- CVE-2024-13890The Allow PHP Execute plugin for WordPress is vulnerable to …7.2
- CVE-2024-13891The Schedule WordPress plugin through 1.0.0 does not sanitis…7.1
- CVE-2024-13892Smartwares cameras CIP-37210AT and C724IP, as well as others…7.7
- CVE-2024-13893Smartwares cameras CIP-37210AT and C724IP, as well as others…7.5
Are you affected by CVE-2024-13888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
