Impact
The vulnerability is an Open Redirection flaw in the WordPress AliNext plugin up to version 3.5.1. An attacker can craft a URL that redirects users to an attacker‑controlled site. While the vulnerability does not directly compromise system data, it can be exploited to facilitate phishing attacks, enabling attackers to lure users into divulging credentials or downloading malware.
Affected Systems
WordPress installations that have the AliNext (Ali2woo‑lite) plugin with versions from the earliest released version up to and including 3.5.1 are affected.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is an attacker‑provided URL that triggers the plugin's redirect function, leading the victim to an untrusted site. The CVSS score of 4.7 indicates a moderate risk, and the EPSS score of < 1% suggests the likelihood of exploitation is low at present. The vulnerability is not listed in CISA KEV. Attackers would likely exploit this weakness by directing a victim to a specially crafted link, leveraging the plugin's redirect feature to send the user to an external, untrusted website.
OpenCVE Enrichment
EUVD