
Cloud Vulnerability DB
A community-led vulnerabilities database
The Event Tickets WordPress plugin before version 5.2.2 contains an open redirect vulnerability (CVE-2021-25028) discovered by Krzysztof Zając and disclosed on December 22, 2021. The vulnerability affects the plugin's handling of the tribe_tickets_redirect_to parameter, which lacks proper validation before redirecting users (WPScan).
The vulnerability is classified as a medium severity issue with a CVSS v3.1 base score of 6.1. The attack vector is network-based (AV:N), with low attack complexity (AC:L), requires no privileges (PR:N), needs user interaction (UI:R), and has a changed scope (S:C) with low impact on both confidentiality and integrity. The vulnerability is tracked as CWE-601 and falls under the OWASP Top 10 category A1: Injection (WPScan, AttackerKB).
When exploited, this vulnerability allows an attacker to perform arbitrary redirects by manipulating the tribe_tickets_redirect_to parameter. This could potentially be used in phishing attacks by redirecting users to malicious websites (WPScan).
A proof of concept exists demonstrating the vulnerability by using the URL pattern: https://example.com/wp-admin/admin.php?page=wp_ajax_rsvp-form&tribe_tickets_redirect_to=https://wpscan.com (WPScan).
The vulnerability has been fixed in Event Tickets version 5.2.2. Users are advised to update to this version or later to mitigate the risk (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."