Impact
An Open Redirect vulnerability exists in Bit Apps Bit Integrations versions up to 2.4.10 that allows an attacker to redirect users to malicious, untrusted sites, thereby facilitating phishing attacks. The weakness maps to CWE-601 and results in a loss of control over where users are directed while they interact with the site.
Affected Systems
The Bit Apps Bit Integrations WordPress plugin, from its earliest released version through 2.4.10 inclusive, is vulnerable. All sites running any of these versions are at risk.
Risk and Exploitability
With a CVSS score of 4.7, the vulnerability is considered medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation at this time; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a lure link that redirects a user to a malicious site, inferred from the described phishing potential and the nature of open redirects when no explicit restriction is applied to user-supplied URLs.
OpenCVE Enrichment
EUVD