Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Aman FunnelKit Automations wp-marketing-automations allows Phishing.This issue affects FunnelKit Automations: from n/a through <= 3.5.1.
Published: 2025-03-27
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Open Redirect flaw that allows an attacker to manipulate redirection URLs processed by the FunnelKit Automations plugin. Because the plugin accepts arbitrary redirect targets without validation, a malicious actor can craft a link that leads users from the legitimate WordPress site to an attacker‑controlled domain, facilitating phishing or malicious site visits. The flaw does not provide direct code execution or data breach but undermines user trust and could compromise credentials if the user follows the deceptive link.

Affected Systems

Delineated vendors: Aman & FunnelKit, product: FunnelKit Automations. The bug exists in all releases up to and including version 3.5.1; earlier releases may or may not be impacted but lack detailed versioning information. Sites running any of these affected plugin versions are susceptible.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate threat potential. The EPSS score is reported as < 1%, which indicates a very low current exploitation probability. The vulnerability is not listed in CISA's KEV catalog, further suggesting it is not actively exploited in the wild. Exploitation requires the ability to construct a URL that triggers the plugin’s redirect logic, most likely via a crafted request to a known endpoint that accepts a redirect query parameter. An attacker then lures users to a malicious domain. While the attack vector is straightforward for someone with access to send phishing emails or posts, the low EPSS reflects limited real‑world exploitation so far.

Generated by OpenCVE AI on May 1, 2026 at 04:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FunnelKit Automations to any version newer than 3.5.1 to remove the vulnerable redirect logic.
  • If an immediate upgrade is not possible, configure the site to intercept or block the redirect endpoint, or restrict its use to trusted users only.
  • Regularly review outgoing links for suspicious redirects and monitor traffic for signs of phishing or malicious link usage.

Generated by OpenCVE AI on May 1, 2026 at 04:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8387 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FunnelKit Automation By Autonami allows Phishing. This issue affects Automation By Autonami: from n/a through 3.5.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FunnelKit Automation By Autonami allows Phishing. This issue affects Automation By Autonami: from n/a through 3.5.1. URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Aman FunnelKit Automations wp-marketing-automations allows Phishing.This issue affects FunnelKit Automations: from n/a through <= 3.5.1.
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FunnelKit Automation By Autonami allows Phishing. This issue affects Automation By Autonami: from n/a through 3.5.1.
Title WordPress Automation By Autonami plugin <= 3.5.1 - Open Redirection vulnerability
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:57.231Z

Reserved: 2025-03-26T09:20:18.314Z

Link: CVE-2025-30795

cve-icon Vulnrichment

Updated: 2025-03-27T13:59:13.449Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:40.753

Modified: 2026-04-23T15:27:05.067

Link: CVE-2025-30795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:15:08Z

Weaknesses